Iranian hackers deploy MiniFast and MiniJunk V2 via phishing and SEO poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (also known as Screening Serpens and UNC1549) is believed to have engaged in a new campaign using decoys impersonating aviation and software organizations across the United States, Europe, and the Middle East following the joint U.S.-Israeli military operation against the country in late February 2026. In […]

Exploiting flaws in KnowledgeDeliver LMS to deploy Godzilla and Cobalt Strike

Rabi LakshmananMay 26, 2026Vulnerability/Threat Intelligence A currently patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a popular learning management system (LMS) in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), results from the use […]

What ClickUp’s mass layoffs say about the future of work

AI’s biggest advocates have argued for some time that the technology will usher in an era of unprecedented productivity gains, greatly rewarding workers who leverage AI and displacing those who don’t. Zeb Evans, CEO of collaboration software startup ClickUp, argues that this change is imminent. Last Thursday, Evans announced on X that the company, which […]

Pope’s AI encyclical isn’t actually about AI

Pope Leo XIV published his first encyclical on Monday. The book, titled Magnifica Humanitas, is about the protection of humans in the age of artificial intelligence. And while AI is the hook, the problems Leo focuses on are older and more widespread. Inequality, war, erosion of democracy, and the concentration of power in the hands […]

Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Ravie LakshmananMay 25, 2026Cybersecurity / Hacking Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times. Phishing […]

Ghost CMS CVE-2026-26980 exploited to hijack over 700 sites in ClickFix attack

Rabi LakshmananMay 25, 2026Vulnerabilities / Web Security Threat actors are exploiting recently revealed critical security flaws in Ghost CMS to inject malicious JavaScript code in order to facilitate ClickFix attacks. According to QiAnXin XLab, this activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), a SQL injection vulnerability in Ghost’s Content API that could allow […]

Alert Firehose is finally here!

Ask cybersecurity experts about Network Detection and Response (NDR) and you may still hear that it’s too noisy and uses too much data. But if you ask teams running NDR that include agent AI capabilities, you’ll hear that they are actually using it to detect threats earlier, triage faster, and reduce false positives. The persistence […]

Lazarus Deploys RemotePE Memory-Only RAT for Financial and Crypto Companies

Rabi LakshmananMay 25, 2026Endpoint security/threat intelligence Cybersecurity researchers have uncovered a cross-platform malware called RemotePE used by the North Korean-linked Lazarus Group in attacks targeting financial institutions and cryptocurrency organizations. According to Fox-IT, a subsidiary of NCC Group, RemotePE is part of a multi-stage attack chain involving two loaders tracked as DPAPILoader and RemotePELoader. “DPAPILoader […]

TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign targets npm, PyPI, and Crates.io and distributes credential-stealing malware. The campaign, codenamed “TrapDoor,” spans over 34 malicious packages across over 384 versions. The oldest activity was recorded on May 22, 2026 at 8:20 PM UTC, when new packages were published to the ecosystem from a cluster […]