New Linux PamDOORa backdoor uses PAM module to steal SSH credentials

Rabi LakshmananMay 8, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed details of a new Linux backdoor named PamDOORa that is being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called “darkworm.” The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that allows persistent SSH access through a combination […]
Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access

Ravi LakshmananMay 7, 2026Vulnerability/Network Security Ivanti warns that a new security flaw affecting Endpoint Manager Mobile (EPMM) is being investigated in limited live attacks. High severity vulnerability CVE-2026-6973 (CVSS score: 7.2) is a case of improper input validation that affects EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. This allows “remote authenticated users with administrative […]
PCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems

Rabi LakshmananMay 7, 2026Threat Intelligence/Cloud Security Cybersecurity researchers have revealed details of a new credential theft framework called PCPJack that targets exposed cloud infrastructure and expels any artifacts linked to TeamPCP from the environment. “This toolset collects credentials from cloud, container, developer, productivity, and financial services, steals data through attacker-controlled infrastructure, and attempts to spread […]
“Patient Zero” Webinar on Eliminating Stealth Breaches

hacker newsMay 7, 2026Artificial intelligence/threat detection The most difficult part of cybersecurity is not technology, but people. The big breaches we’ve read about lately usually start the same way: one employee, one well-crafted email, one “Patient Zero” infection. In 2026, hackers are using AI to make these “first clicks” nearly impossible to identify. Do you […]
PAN-OS RCE exploit is actively used to allow root access and espionage

Rabi LakshmananMay 7, 2026Vulnerabilities/Cyber Espionage Palo Alto Networks has disclosed that attackers may have unsuccessfully attempted to exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question, CVE-2026-0300 (CVSS score: 9.3/8.7), is a buffer overflow vulnerability in the User Identity Authentication Portal service of Palo Alto Networks PAN-OS […]
Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories

Ravie LakshmananMay 07, 2026Hacking News / Cybersecurity News Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack chains don’t even feel sophisticated […]
The Operational Gaps That Break Incident Response

Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer the phone. Operational readiness determines whether that team can do meaningful work the moment they do. That distinction matters far more than many organizations realize. In […]
PyPI package delivers ZiChatBot malware via Zulip API on Windows and Linux

Ravi LakshmananMay 7, 2026Malware/Threat Intelligence Cybersecurity researchers have discovered three packages in the Python Package Index (PyPI) repository designed to covertly deliver a previously unknown malware family called ZiChatBot to Windows and Linux systems. “While these wheel packages implement the functionality described on the PyPI web page, their true purpose is to covertly deliver malicious […]
Vulnerability in vm2 Node.js library allows sandbox escape and arbitrary code execution

Ravi LakshmananMay 7, 2026Vulnerabilities/Software Security More than a dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by malicious actors to breach the sandbox and execute arbitrary code on susceptible systems. vm2 is an open source library used to run untrusted JavaScript code in a secure sandbox by […]
Mirai-based xlabs_v1 botnet exploits ADB to hijack IoT devices and launch DDoS attacks

Cybersecurity researchers have published a new Mirai-derived botnet that targets internet-exposed devices that self-identify as xlabs_v1 and are running Android Debug Bridge (ADB), allowing them to join the network to perform distributed denial of service (DDoS) attacks. Hunt.io, which detailed the malware, said it discovered it after identifying a published directory on a server with […]