Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak […]
Open source tools maker Grafana Labs says hackers stole its code and refuses to pay ransom

Grafana Labs, the maker of the popular open source web visualization software that bears the company’s name, acknowledged that it had been hacked but announced that it refused to pay the hackers who threatened to expose its codebase. In a series of social media posts, the institute said its investigation found that hackers misused stolen […]
How to reduce phishing exposure before it leads to business disruption

What if a phishing email seems safe enough to get past security, but is dangerous enough to expose your business with just one click? That’s the gap that many SOCs still have. The attack left the team unsure of what was exposed, who else was targeted, and how far the risk spread. Detecting phishing early […]
Developer workstations are now part of the software supply chain

Supply chain attackers aren’t just trying to sneak malicious code into trusted software. They seek to steal access that enables trusted software. Recently, three separate campaigns attacked npm, PyPI, and Docker Hub within 48 hours, targeting three secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is […]
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL injection, privilege escalation flaw

Ravi LakshmananMay 18, 2026Vulnerabilities/Software Security Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by malicious parties to bypass authentication and execute arbitrary code. Topping the list is a critical flaw affecting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited for information disclosure or client-side […]
Get lifetime access to this gamified language learning app for just $49

TL;DR: Get a lifetime subscription to Qlango Language Learning for $49 (Reg. $239). This is an 80% discount on a gamified app that helps you memorize vocabulary through spaced repetition. Learning a new language usually means getting hooked on subscription plans, feeling pressured to keep up a streak, and using apps that never really click. […]
Four malicious npm packages deliver information theft and Phantom Bot DDoS malware

Ravi LakshmananMay 18, 2026Supply chain attack/botnet Cybersecurity researchers have discovered four new npm packages containing information-stealing malware. One of them is a clone of the Shai-Hulud worm that was open sourced by TeamPCP. The list of identified packages is below – chalk-tempalte (825 downloads) @deadcode09284814/axios-util (284 downloads) axois-utils (963 downloads) color-style-utils (934 downloads) “One of […]
Stuxnet Fast16 and earlier malware tampers with nuclear weapon simulation

Ravi LakshmananMay 18, 2026Industrial sabotage/malware New analysis of the Lua-based fast16 malware confirms that it is a cyber-jamming tool designed to tamper with nuclear weapons test simulations. The Broadcom-owned Symantec and Carbon Black teams say tools before Stuxnet were designed to subvert uranium compression simulations, which are central to nuclear weapons design. “Fast16’s hook engine […]
MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

Ravi LakshmananMay 18, 2026Zero-day/vulnerabilities Chaotic Eclipse, the security researchers behind the recently revealed Windows flaws YellowKey and GreenPlasma, has released a proof of concept (PoC) for a Windows privilege escalation zero-day flaw that grants an attacker SYSTEM privileges on a fully patched Windows system. Codenamed MiniPlasma, the vulnerability affects ‘cldflt.sys’, which refers to the Windows […]
Apple’s Siri revamp could include automatic chat deletion

According to Bloomberg’s Mark Garman, privacy will be a major theme when Apple unveils a new version of Siri at its Worldwide Developers Conference in June. The relaunch of Siri is widely seen as a major opportunity for Apple to reestablish its relevance in artificial intelligence. As part of that effort, Garman said, company executives […]