// 6 ZERO-DAY · 8 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
cybersec

PyPI: Package with 1.1 Million Downloads Hacked to Distribute Infostealer

A PyPI package with 1.1 million monthly downloads was compromised to distribute an infostealer. Analysis of the software supply chain…

Apr 28, 2026views - 175

CYBERSEC

Chinese Hacker Extradited to the US: The Xu Zewei Case

Xu Zewei, an alleged Hafnium member arrested in Milan, was extradited to the US. Accused of stealing COVID research, the case sparks a…

Apr 27, 2026views - 152

CYBERSEC

GlassWorm v2: 73 Fake VS Code Extensions Discovered on Open VSX

A cluster of 73 malicious extensions linked to GlassWorm v2 discovered on Open VSX. Attackers use sleeper packages to evade security c…

Apr 27, 2026views - 183

CYBERSEC

IRSF Fraud via Fake CAPTCHAs: Analysis of the Campaign Active Since 2020

Over 120 campaigns use Keitaro TDS to distribute IRSF scams via fake CAPTCHAs. 17 countries hit, costs up to $30 per victim. Here are…

Apr 27, 2026views - 186

ai

2023 Flashback: ChatGPT, the Privacy Authority Block, and Data Management

2023 Retrospective: From the Italian Privacy Authority’s ChatGPT ban for non-compliance to the technical glitch exposing Plus users' d…

Apr 27, 2026views - 238

CYBERSECEXPLOIT

April 2026 CISA KEV: 12 Vulnerabilities in a Week, Ransomware Alert

CISA added 12 exploited vulnerabilities to the KEV catalog from April 20-24, 2026. SimpleHelp, D-Link, and Samsung are among the affec…

Apr 25, 2026views - 240

CYBERSECCRITICAL

Pack2TheRoot: Critical Linux Passwordless Root Vulnerability

Pack2TheRoot (CVE-2026-41651) affects Linux PackageKit for 12 years. CVSS 8.8, local passwordless root access. Patches available: here…

Apr 24, 2026views - 217