// 3 CVE · 2 EXPLOIT IN THE LAST 24H
CYBERSEC

Entra ID Vulnerability: Patch for Agent ID Privilege Escalation

Microsoft fixed a vulnerability in Entra ID's Agent ID Administrator role. The bug allowed high-privilege service principal takeover.…

Apr 28, 2026views - 218

cybersec

PyPI: Package with 1.1 Million Downloads Hacked to Distribute Infostealer

A PyPI package with 1.1 million monthly downloads was compromised to distribute an infostealer. Analysis of the software supply chain…

Apr 28, 2026views - 171

CYBERSEC

Chinese Hacker Extradited to the US: The Xu Zewei Case

Xu Zewei, an alleged Hafnium member arrested in Milan, was extradited to the US. Accused of stealing COVID research, the case sparks a…

Apr 27, 2026views - 144

CYBERSEC

GlassWorm v2: 73 Fake VS Code Extensions Discovered on Open VSX

A cluster of 73 malicious extensions linked to GlassWorm v2 discovered on Open VSX. Attackers use sleeper packages to evade security c…

Apr 27, 2026views - 175

CYBERSEC

IRSF Fraud via Fake CAPTCHAs: Analysis of the Campaign Active Since 2020

Over 120 campaigns use Keitaro TDS to distribute IRSF scams via fake CAPTCHAs. 17 countries hit, costs up to $30 per victim. Here are…

Apr 27, 2026views - 174

ai

2023 Flashback: ChatGPT, the Privacy Authority Block, and Data Management

2023 Retrospective: From the Italian Privacy Authority’s ChatGPT ban for non-compliance to the technical glitch exposing Plus users' d…

Apr 27, 2026views - 230

CYBERSECEXPLOIT

April 2026 CISA KEV: 12 Vulnerabilities in a Week, Ransomware Alert

CISA added 12 exploited vulnerabilities to the KEV catalog from April 20-24, 2026. SimpleHelp, D-Link, and Samsung are among the affec…

Apr 25, 2026views - 228

CYBERSECCRITICAL

Pack2TheRoot: Critical Linux Passwordless Root Vulnerability

Pack2TheRoot (CVE-2026-41651) affects Linux PackageKit for 12 years. CVSS 8.8, local passwordless root access. Patches available: here…

Apr 24, 2026views - 205