MetInfo CMS CVE-2026-29014 can be exploited for remote code execution attacks

Ravi LakshmananMay 5, 2026Vulnerability/Network Security Threat actors are actively exploiting a critical security flaw affecting the open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), which is a code injection flaw that could lead to arbitrary code execution. The NIST National […]

We scanned 1 million publicly available AI services. How Bad Is Security Really?

The software industry has made real strides in delivering products securely over the past few decades, but the breakneck pace of AI adoption is putting that progress at risk. The promise of AI as a power multiplier and the pressure to deliver more value, faster, are driving companies to rapidly migrate to self-hosted LLM infrastructure. […]

ScarCruft hacks gaming platforms and deploys BirdCall malware on Android and Windows

Ravi LakshmananMay 5, 2026Cyber ​​espionage/surveillance A North Korean-aligned state-sponsored hacker group known as ScarCruft compromised video gaming platforms with supply chain espionage attacks and trojanized their components with a backdoor called BirdCallto, likely targeting ethnic Koreans living in China. While previous versions of the backdoor primarily targeted only Windows users, the supply chain attack is […]

Weaver E-cology RCE flaw CVE-2026-22679 can be actively exploited via the debug API

Ravi LakshmananMay 5, 2026Vulnerability/Network Security A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has been exploited in the wild. This vulnerability (CVE-2026-22679, CVSS score: 9.8) is related to an unauthenticated remote code execution case that affects Weaver E-cology 10.0 versions prior to 20260312. The issue exists in […]

Microsoft details phishing campaign that targeted 35,000 users in 26 countries

Microsoft has revealed details of a large-scale credential theft campaign that combines decoy-themed code with legitimate email services to lure users to attacker-controlled domains and steal authentication tokens. This multi-stage campaign, observed from April 14th to 16th, 2026, targeted over 35,000 users in over 13,000 organizations across 26 countries, with 92% of targets located in […]

Phishing campaign using SimpleHelp and ScreenConnect RMM tools hits over 80 organizations

Ravi LakshmananMay 4, 2026Network security/endpoint security Since at least April 2025, we have observed active phishing campaigns targeting multiple vectors, using legitimate remote monitoring and management (RMM) software as a way to establish persistent remote access to compromised hosts. According to Securonix, the operation, codenamed VENOMOUS#HELPER, has affected more than 80 organizations, most of them […]

Progress on patching critical MOVEit automation bug to enable authentication bypass

Ravi LakshmananMay 4, 2026Vulnerabilities / Enterprise Software Progress Software has released an update that addresses two security flaws in MOVEit Automation, including a critical bug that could lead to authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments […]

AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

Ravie LakshmananMay 04, 2026Cybersecurity / Hacking This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside […]

The year of AI-assisted attacks

On December 4, 2025, a 17-year-old boy was arrested in Osaka under Japan’s Unauthorized Access Prevention Act. The young man was running malicious code that extracted the personal data of more than 7 million users of Kaikatsu Club, Japan’s largest internet cafe chain. When asked, the young man explained his motivation for the hack. Because […]

Silver Fox deploys ABCDoor malware in India and Russia via tax-themed phishing

Ravi LakshmananMay 4, 2026Malware/Network Security A China-based cybercrime group known as Silver Fox is said to be involved in a new campaign targeting organizations in Russia and India using a new malware called ABCDoor. The campaign used a phishing email mimicking a communication from India’s Income Tax Department in December 2025, followed by a similar […]