LMDeploy CVE-2026-33626 flaw exploited within 13 hours of publication

A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, unpacking, and serving LLMs, has become exploitable in the wild less than 13 hours after its disclosure. This vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), is related to server-side request forgery (SSRF) vulnerabilities and can be exploited to access sensitive data. “LMDeploy’s vision language […]

UNC6692 Deploying SNOW malware by impersonating IT helpdesk via Microsoft Teams

A previously undocumented cluster of threat activity known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy custom malware suites on compromised hosts. “Like many other intrusions in recent years, UNC6692 relied heavily on impersonating IT help desk employees to persuade victims to accept Microsoft Teams chat invitations from accounts […]

Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

According to new findings from JFrog and Socket, the Bitwarden CLI was compromised as part of a newly discovered and ongoing Checkmarx supply chain campaign. “The version of the affected package appears to be @bitwarden/cli@2026.4.0, and the malicious code was exposed in the file ‘bw1.js’ included in the package contents,” the application security company said. […]

$290M DeFi Hack, macOS LoL Abuse, ProxySmart SIM Farms +25 New Stories

Ravie LakshmananApr 23, 2026Hacking News / Cybersecurity News You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. […]

Defeat automated exploits at the speed of AI

hacker newsApril 23, 2026Artificial Intelligence/Enterprise Security Imagine a world where hackers don’t sleep, don’t take breaks, and find weaknesses in systems instantly. Well, that world is already there. Thanks to AI, attackers can now execute large-scale, automated exploits faster than ever before. The time to remediate vulnerabilities before being attacked has been reduced to zero. […]

Project Glasswing proved that AI can find bugs. Who will fix it?

Last week, Anthropic announced Project Glasswing, an AI model so effective at finding vulnerabilities in software, that it took the unusual step of delaying its public release. Instead, the company granted access to Apple, Microsoft, Google, Amazon, and other allied companies so they could find and patch bugs before adversaries did. Mythos Preview, the model […]

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Ravi LakshmananApril 23, 2026Threat Intelligence/Malware Mongolian government agencies have emerged as targets of a previously undocumented China-aligned Advanced Persistent Threat (APT) group tracked as GopherWhisper. “The group leverages a wide range of tools, primarily written in Go, and uses injectors and loaders to deploy and execute various backdoors in its arsenal,” Slovak cybersecurity firm ESET […]

Vercel finds more compromised accounts in breach related to Context.ai

Ravi LakshmananApril 23, 2026Artificial Intelligence / SaaS Security Vercel said Wednesday that it has identified a set of additional customer accounts that were compromised as part of a security incident that allowed unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an additional set of […]

Apple patches iOS flaw that saved Signal notifications deleted in FBI investigation

Ravi LakshmananApril 23, 2026Vulnerabilities/Encryption Apple has released a software fix for iOS and iPadOS to address a flaw in the Notifications service that stores notifications marked for deletion on the device. This vulnerability is tracked as CVE-2026-28950 (CVSS score: N/A) and is described as a logging issue that is resolved with improved data redacting. “Notifications […]

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

Ravi LakshmananApril 22, 2026Cloud security/software security Cybersecurity researchers have warned about malicious images being pushed to the official “checkmarx/kics” Docker Hub repository. Socket, a software supply chain security company, revealed in an alert published today that an unknown attacker was able to successfully overwrite existing tags, including v2.1.20 and alpine, while simultaneously introducing a new […]