Your purple team is not purple – just red and blue in the same room

The network defense at 2:00 a.m. looks like this: The analyst copies the hash from the PDF and pastes it into the SIEM query. The red team’s script has been manually rewritten for use by the blue team. The patch is awaiting a change approval period that is longer than the exploitation period itself. There […]

Fake OpenAI privacy filter repository hits #1 spot with ‘hug face’, attracts 244,000 downloads

Ravi LakshmananMay 11, 2026Supply chain attack/threat intelligence The malicious Hugging Face repository made its way onto the platform’s trending list by impersonating OpenAI’s privacy filter’s openweight model and delivering a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, pretended to be the legitimate version released by OpenAI late last month (openai/privacy-filter) and copied […]

How to Test a Salesforce Experience Site Like an Apex Predator

As the foremost CRM solution, Salesforce is often considered the preeminent SaaS platform. It is used by companies from small start-ups to major corporations. And many of those companies use Salesforce Experience Cloud to run native sites – that run on their Salesforce and are deeply integrated with it. Those web apps are powerful and […]

OAuth and MCP investigation checklist

OAuth permissions are the silent back door of modern SaaS, and with the rise of remote MCP servers, that back door is only getting wider. Every time an employee clicks “Sign in with Google” or connects an AI agent to a new MCP server, another vendor obtains the key to the data, often without IT […]

Ollama out-of-bounds read vulnerability causes remote process memory leak

Cybersecurity researchers have revealed that Ollama has significant security vulnerabilities. Successful exploitation of this vulnerability could allow a remote, unauthenticated attacker to leak entire process memory. This out-of-bounds read flaw can impact over 300,000 servers worldwide and is tracked as CVE-2026-7482 (CVSS score: 9.1). Codenamed Bleeding Llama by Cyera. Ollama is a popular open source […]

cPanel WHM Releases Fixes for 3 New Vulnerabilities – Patch Now

Ravi LakshmananMay 9, 2026Vulnerabilities / Web Hosting cPanel has released updates that address three vulnerabilities in cPanel and Web Host Manager (WHM). These vulnerabilities can be exploited to achieve privilege escalation, code execution, and denial of service. Here is the list of vulnerabilities: CVE-2026-29201 (CVSS score: 4.3) – Insufficient input validation of the feature file […]

TCLBANKER banking Trojan targets financial platforms via WhatsApp and Outlook worms

Threat hunters flagged a previously undocumented Brazilian banking Trojan called TCLBANKER. This Trojan can target 59 banking, fintech, and cryptocurrency platforms. This activity is tracked by Elastic Security Labs under the name REF3076. This malware family is rated as a major update to Maverick and is known to utilize a worm called SORVEPOTEL to spread […]

Fake call history app steals payments from users after 7.3 million downloads on Play Store

Ravi LakshmananMay 8, 2026Android/mobile security Cybersecurity researchers have discovered a fraudulent app on the official Google Play Store for Android that pretends to provide access to the call history of any phone number, only to trick users into providing fake data and signing up for a subscription that incurs financial loss. The 28 apps had […]

Quasar Linux RAT steals developer credentials in software supply chain compromise

Ravi LakshmananMay 8, 2026Linux/DevOps The previously undocumented Linux implant, codenamed Quasar Linux RAT (QLNX), targets developers’ systems to not only establish a silent foothold, but also facilitate a wide range of post-compromise functions, including credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling. “QLNX targets developers and DevOps credentials across the software supply chain,” […]

What 25 million alerts reveal about low-severity risks

The dark secret of corporate security operations is that defenders have quietly institutionalized the habit of not looking. This is not just an anecdote, but is backed up by a recent report that examined over 25 million security alerts, including informational and low-severity alerts, across real-world enterprise environments. The dataset behind these findings includes telemetry […]