Malicious npm package stole files from Claude AI user directory via GitHub

Rabi LakshmananMay 27, 2026Threat Intelligence/Supply Chain Attacks Cybersecurity researchers have discovered a new malicious package on the npm registry with information-stealing capabilities. According to OX Security, the package, named mouse5212-super-formatter, is designed to upload files from /mnt/user-data. This is a dedicated directory used by Anthropic’s Claude artificial intelligence (AI) tool to process uploads and output […]
5 steps to manage shadow AI tools without degrading employee performance

When employees install an AI writing assistant, connect Coding CoPilot to their IDE, or start summarizing a meeting using a new browser tool, they’re doing exactly what productive employees should be doing: finding ways to work faster. In most organizations today, employees run three to five AI tools a day. Most were never reviewed by […]
GlassWorm malware removal disrupts developer supply chain attack infrastructure

Rabi LakshmananMay 27, 2026Malware/Threat Intelligence CrowdStrike announced that it is partnering with Google and the Shadowserver Foundation to simultaneously disrupt all command and control (C2) channels associated with GlassWorm, a persistent software chain campaign that targets software developers through malicious packages and extensions. “Since at least early 2025, GlassWorm operators have systematically targeted software developers, […]
Three SOC steps to shut down incident risk early

Most organizations still view cyber defense as a fortress issue. Build stronger walls, add guards, buy different detection engines. But modern incidents rarely break through the front gates. They drift around under the guise of routine activity, hide behind legitimate processes, and quietly accumulate risk long before anyone calls it an “incident.” This completely changes […]
Gitea vulnerability allows private container images to be exposed without authentication

Rabi LakshmananMay 27, 2026Vulnerabilities/Software Security Cybersecurity researchers have revealed a security flaw in Gitea, an open source self-hosted platform for version control. This flaw allows an unauthenticated, remote attacker to obtain private container images from a Gitea deployment without requiring an account, password, or other credentials. This vulnerability is tracked as CVE-2026-27771 (CVSS score: N/A) […]
AI chatbot recommendations redirect users to cryptojacking malware site

Microsoft has warned of an active cryptojacking campaign that uses artificial intelligence (AI) chatbot interactions as a mechanism to display malicious download sites. “This new delivery technology extends social engineering beyond traditional search results and increases the visibility of malicious software recommendations,” Microsoft Defender Experts and the Microsoft Defender Security Research Team said in a […]
MuddyWater uses DLL sideloading to spy on nine countries

The Iranian hacker group known as Muddywater is said to be behind a new campaign that will affect at least nine organizations in nine countries on four continents in the first quarter of 2026. According to Symantec and Carbon Black’s Threat Hunter Team, the activity targeted industrial and electronics manufacturing, education and public sector entities, […]
New AI DDoS attacks are getting smarter. Learn how to fight back with this webinar

hacker newsMay 26, 2026Web security/artificial intelligence Every day, hackers find new ways to crash websites and steal data. But now something has changed. Hackers no longer operate alone. They are now using powerful artificial intelligence (AI) tools to make their attacks faster, more powerful, and much harder to stop. According to a recent update on […]
Microsoft patches SharePoint RCE flaw CVE-2026-45659 across server versions

Rabi LakshmananMay 26, 2026Vulnerabilities / Enterprise Security Microsoft has released an update that fixes a remote code execution vulnerability affecting SharePoint. This vulnerability could be exploited by a malicious attacker without any special conditions being met. This vulnerability is tracked as CVE-2026-45659 and has a CVSS score of 8.8. It has been assigned a severity […]
Why the second element won’t save you

Multi-factor authentication (MFA) was seen as filling a critical gap in identity security. This means that even if an attacker has the account credentials, they will not be able to log in without the second factor. This logic was good, but the attacker realized that he didn’t need to steal the second element, he just […]