Cybersecurity
204 articles RSS
npm Ships Staged Publishing and Install-Source Allowlists in CLI 11.15.0, Requiring Human 2FA Approval Before Packages Go Live
GitHub's npm registry makes staged publishing generally available: packages must pass a human-approved, 2FA-gated queue before consumers can install them.
Laravel-Lang Supply Chain Attack Poisons Over 700 Package Versions via Packagist Tag Hijack, Deploying Cross-Platform Credential Stealer
Attackers rewrote Git tags across four Laravel localization packages to point to malicious forks, poisoning hundreds of versions and deploying a credential stealer targeting cloud keys, SSH, and crypto wallets.
Iranian APT MuddyWater Deployed Chaos Ransomware as a False Flag to Disguise State-Sponsored Espionage
Rapid7 links a Chaos ransomware intrusion in early 2026 to Iranian state-linked MuddyWater, finding no encryption deployed — only credential theft and data exfiltration under ransomware cover.
Google GTIG Confirms First Criminal AI-Built Zero-Day: A 2FA Bypass That Would Have Enabled Mass Exploitation
Google's Threat Intelligence Group says a cybercrime group built a zero-day exploit using AI, marking the first confirmed case of adversaries weaponizing an LLM to discover and exploit a previously unknown vulnerability.
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector for First Time in 19 Years
The 2026 DBIR finds 31% of breaches now begin with unpatched vulnerabilities -- surpassing credential abuse for the first time in the report's 19-year history -- as median patch time climbs to 43 days and ransomware reaches 48% of all breaches.
Microsoft Dismantles Fox Tempest, a Malware-Signing Service That Issued Over a Thousand Fraudulent Certificates Through Azure
Microsoft's Digital Crimes Unit seized signspace.cloud and revoked more than 1,000 fraudulent code-signing certificates after Fox Tempest sold access to Azure Artifact Signing for $5,000–$9,000 per transaction to ransomware groups including Rhysida, Akira, and Qilin.
MiniPlasma: A Five-Year-Old Windows Zero-Day Resurfaces With Working PoC, Granting SYSTEM Privileges on Fully Patched Systems
A researcher named Chaotic Eclipse released a working exploit for an unpatched Windows privilege escalation flaw in the Cloud Filter driver, confirmed to grant SYSTEM access on fully patched Windows 11.
Pwn2Own Berlin 2026 Closes With $1.3 Million in Prizes and 47 Zero-Days as DEVCORE Claims Master of Pwn
DEVCORE took the top prize with $505,000 and 50.5 points after three days at OffensiveCon, where 47 unique zero-days in Windows, Exchange, VMware, and AI tools earned researchers $1,298,250.
Mini Shai-Hulud Worm Hits TanStack, Mistral AI and UiPath, Compromising 170+ npm and PyPI Packages With 518M Combined Downloads
TeamPCP's May 11 supply-chain attack abused a pull_request_target workflow, GitHub Actions cache poisoning, and OIDC token theft to ship 84 malicious TanStack versions and spread to Mistral AI, UiPath and others.
Microsoft Confirms Active Exploitation of Unpatched Exchange Server CVE-2026-42897 as CISA Adds It to KEV With May 29 Deadline
Microsoft has disclosed an actively exploited cross-site scripting flaw in on-premises Exchange Server's Outlook Web Access. No patch has shipped; CISA gave federal agencies until May 29 to apply mitigations.
DepthFirst's AI Scanner Surfaces NGINX Rift, an 18-Year-Old Heap Overflow in the Rewrite Module That Enables Unauthenticated RCE
An LLM-powered scanner from security startup DepthFirst flagged a heap buffer overflow that had sat undetected in NGINX's rewrite module for roughly 18 years, prompting F5 to ship coordinated patches on May 13.
Cisco Patches Sixth SD-WAN Zero-Day of 2026 as CISA Adds CVE-2026-20182 to KEV With Three-Day Federal Deadline
A second authentication bypass in the same vdaemon stack as February's CVE-2026-20127 carries a CVSS 10.0 and is being exploited by the same UAT-8616 cluster, Cisco and Talos disclosed on May 14.