Two cybersecurity experts sentenced to four years in prison for BlackCat ransomware attack

Ravi LakshmananMay 1, 2026Data Breach/Law Enforcement The US Department of Justice (DoJ) announced Thursday that two cybersecurity experts will each be sentenced to four years in prison for facilitating the 2023 BlackCat ransomware attack. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, are accused of deploying ransomware to multiple victims across the […]
Tainted Ruby Gems and Go Modules Abuse CI Pipelines to Steal Credentials

Ravi LakshmananMay 1, 2026Supply chain attacks/malware New software supply chain attack campaigns have been observed using sleeper packages as a vector to then push malicious payloads that enable credential theft, GitHub Actions modification, and SSH persistence. This activity is believed to be the work of the GitHub account ‘BufferZoneCorp’, which published a set of repositories […]
PyTorch Lightning and Intercom Client Suffer Supply Chain Attack to Steal Credentials

Ravi LakshmananApril 30, 2026Supply chain attacks/malware In yet another software supply chain attack, attackers compromised the popular Python package Lightning and pushed two malicious versions to perform credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both published on April 30, 2026. The campaign […]
SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

Ravie LakshmananApr 30, 2026Hacking News / Cybersecurity News The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to […]
New Python backdoor uses tunneling service to steal browser and cloud credentials

Ravi LakshmananApril 30, 2026Cloud security/threat intelligence Cybersecurity researchers have revealed details of a stealth Python-based backdoor framework called DEEP#DOOR that has the ability to establish persistent access and collect a wide range of sensitive information from compromised hosts. “The compromise chain begins with the execution of a batch script (‘install_obf.bat’) that disables Windows security controls, […]
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers, and security analysts by impersonating administrative utilities they rely on for daily operations. By integrating Search Engine Order (SEO) poisoning, a dual-stage GitHub distribution architecture, and decentralized blockchain-based […]
New Linux ‘copy failure’ vulnerability allows root access on major distributions

Ravi LakshmananApril 30, 2026Linux / Vulnerabilities Cybersecurity researchers have revealed details of a Linux local privilege escalation (LPE) flaw that could allow unprivileged local users to gain root. This high-severity vulnerability, tracked as CVE-2026-31431 (CVSS score: 7.8), has been codenamed Copy Fail by Xint.io and Theori. “An unprivileged local user can write a controlled 4 […]
Google fixes issue with CVSS 10 Gemini CLI CI RCE and cursor flaw that could allow code execution

Google has addressed a maximum severity security flaw in the Gemini CLI (the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow). This flaw could allow an attacker to execute arbitrary commands on the host system. “This vulnerability could allow an unauthorized external attacker to force load their own malicious content as a Gemini configuration,” […]
SAP-related npm packages compromised in supply chain attack that steals credentials

Ravi LakshmananApril 29, 2026Supply chain attacks/malware Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm packages that contain credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign, dubbed Mini Shai-Hulud, affected the following packages related to SAP’s JavaScript and cloud application […]
New wave of North Korean attacks using AI-embedded npm malware, fake companies, and RATs

Cybersecurity researchers discovered malicious code within an npm package following the malicious package as a dependency to a project by Anthropic’s Claude Opus Large-Scale Language Model (LLM). The package in question is “@validate-sdk/v2” and is listed on npm as a utility software development kit (SDK) for hashing, validation, encoding/decoding, and secure random generation. However, its […]