Stuxnet Fast16 and earlier malware tampers with nuclear weapon simulation

Ravi LakshmananMay 18, 2026Industrial sabotage/malware New analysis of the Lua-based fast16 malware confirms that it is a cyber-jamming tool designed to tamper with nuclear weapons test simulations. The Broadcom-owned Symantec and Carbon Black teams say tools before Stuxnet were designed to subvert uranium compression simulations, which are central to nuclear weapons design. “Fast16’s hook engine […]

MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

Ravi LakshmananMay 18, 2026Zero-day/vulnerabilities Chaotic Eclipse, the security researchers behind the recently revealed Windows flaws YellowKey and GreenPlasma, has released a proof of concept (PoC) for a Windows privilege escalation zero-day flaw that grants an attacker SYSTEM privileges on a fully patched Windows system. Codenamed MiniPlasma, the vulnerability affects ‘cldflt.sys’, which refers to the Windows […]

NGINX CVE-2026-42945 can be exploited in the wild to cause worker crash and possible RCE

Ravi LakshmananMay 17, 2026Server security/vulnerabilities According to VulnCheck, a newly disclosed security flaw affecting NGINX Plus and NGINX Open has become exploitable in the wild just days after its publication. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module that affects NGINX versions 0.6.27 through 1.30.0. According to AI-native […]

Grafana GitHub token compromise led to codebase downloads and extortion attempts

Ravi LakshmananMay 17, 2026Data breach/cyber crime Grafana revealed that an “unauthorized party” obtained a token that gave them permission to access the company’s GitHub environment and download its codebase. “Our investigation has determined that no customer data or personal information was accessed in this incident, and we found no evidence of any impact on customer […]

Actively exploited funnel builder flaw allows WooCommerce checkout skimming

Ravi LakshmananMay 16, 2026Vulnerabilities / Website Security A critical security vulnerability affecting the Funnel Builder plugin for WordPress has been exploited to inject malicious JavaScript code into WooCommerce checkout pages with the purpose of stealing payment data. Details of the activities were announced by Sunsec this week. This vulnerability currently does not have a formal […]

Turla turns Kazuar backdoor into modular P2P botnet for persistent access

Ravi LakshmananMay 15, 2026Botnet/Threat Intelligence A Russian state-sponsored hacking group known as Turla transformed the custom backdoor Katar into a modular peer-to-peer (P2P) botnet designed for stealthy and persistent access to compromised hosts. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Turla has been assessed as belonging to Center 16 of Russia’s Federal […]

Four OpenClaw flaws allow data theft, privilege escalation, and persistence

Ravi LakshmananMay 15, 2026Vulnerability/AI Security Cybersecurity researchers have revealed a series of four security flaws in OpenClaw that can be chained together to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively referred to as “Claw Chain” by Cyera, could allow attackers to establish a foothold, expose sensitive data, and install backdoors. A brief […]

What you can learn about your real attack surface by observing your tools for 45 days

hacker newsMay 15, 2026Endpoint security/threat detection In “The Biggest Security Risk Isn’t Malware — It’s What You Already Trust,” I made the simple argument that the most dangerous activity within most organizations no longer looks like an attack. It’s administrative-like. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities that IT teams use every […]

TanStack supply chain attack attacks two OpenAI employee devices, forcing macOS updates

OpenAI disclosed that two of its employee devices in its corporate environment were affected by the Mini Shai-Hulud supply chain attack on TanStack, but said that no user data, production systems, or intellectual property was compromised or modified in an unauthorized manner. “Once we identified the malicious activity, we quickly took steps to investigate, contain, […]

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

Rabi LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability affecting the on-premises version of Exchange Server and announced that it is being exploited in the wild. The vulnerability is tracked as CVE-2026-42897 (CVSS score: 8.1) and is described as a spoofing bug due to a cross-site scripting flaw. An anonymous researcher […]