CERT-In mandates 12-hour patching for internet-facing flaws during AI-assisted attacks

The Computer Emergency Response Team of India (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged, in order to automate vulnerability discovery and exploitation and protect against potential threats arising from the misuse of artificial intelligence (AI) tools and large-scale language models (LLM) […]
Iranian hackers deploy MiniFast and MiniJunk V2 via phishing and SEO poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (also known as Screening Serpens and UNC1549) is believed to have engaged in a new campaign using decoys impersonating aviation and software organizations across the United States, Europe, and the Middle East following the joint U.S.-Israeli military operation against the country in late February 2026. In […]
Exploiting flaws in KnowledgeDeliver LMS to deploy Godzilla and Cobalt Strike

Rabi LakshmananMay 26, 2026Vulnerability/Threat Intelligence A currently patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a popular learning management system (LMS) in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), results from the use […]
Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Ravie LakshmananMay 25, 2026Cybersecurity / Hacking Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times. Phishing […]
Ghost CMS CVE-2026-26980 exploited to hijack over 700 sites in ClickFix attack

Rabi LakshmananMay 25, 2026Vulnerabilities / Web Security Threat actors are exploiting recently revealed critical security flaws in Ghost CMS to inject malicious JavaScript code in order to facilitate ClickFix attacks. According to QiAnXin XLab, this activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), a SQL injection vulnerability in Ghost’s Content API that could allow […]
Alert Firehose is finally here!

Ask cybersecurity experts about Network Detection and Response (NDR) and you may still hear that it’s too noisy and uses too much data. But if you ask teams running NDR that include agent AI capabilities, you’ll hear that they are actually using it to detect threats earlier, triage faster, and reduce false positives. The persistence […]
Lazarus Deploys RemotePE Memory-Only RAT for Financial and Crypto Companies

Rabi LakshmananMay 25, 2026Endpoint security/threat intelligence Cybersecurity researchers have uncovered a cross-platform malware called RemotePE used by the North Korean-linked Lazarus Group in attacks targeting financial institutions and cryptocurrency organizations. According to Fox-IT, a subsidiary of NCC Group, RemotePE is part of a multi-stage attack chain involving two loaders tracked as DPAPILoader and RemotePELoader. “DPAPILoader […]
TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign targets npm, PyPI, and Crates.io and distributes credential-stealing malware. The campaign, codenamed “TrapDoor,” spans over 34 malicious packages across over 384 versions. The oldest activity was recorded on May 22, 2026 at 8:20 PM UTC, when new packages were published to the ecosystem from a cluster […]
npm adds 2FA gate exposure and package installation controls for supply chain attacks

Rabi LakshmananMay 23, 2026Software Supply Chain / DevSecOps To improve security in the software supply chain, GitHub has rolled out new controls in npm that allow maintainers to explicitly approve releases before a package is publicly available for installation. This feature, called gradual rollout, is currently generally available on npm. A human maintainer is required […]
Packagist supply chain attack infects 8 packages using Linux malware hosted on GitHub

Rabi LakshmananMay 23, 2026Malware / DevSecOps A new “coordinated” supply chain attack campaign affected eight packages on Packagist that contained malicious code designed to execute Linux binaries retrieved from GitHub release URLs. “The affected packages were all Composer packages, but the malicious code was not added to composer.json,” Socket said. “Instead, it was inserted into […]