// 1 CRITICAL · 5 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
malware

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere

Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

May 06, 2026views - 176

CYBERSEC

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence

At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

May 06, 2026views - 106

CYBERSEC

Vimeo Data Breach: 119,200 Emails Exposed via Anodot Integration

In May 2026, the ShinyHunters threat group published a 106 GB Vimeo archive stolen via the anomaly detection platform Anodot. The leak…

May 05, 2026views - 125

CYBERSEC

Vishing and AiTM Bypass MFA: Invisible Extortion in SaaS

Criminal groups like Cordial Spider use vishing and AiTM to bypass MFA and target SaaS environments. Protect your corporate data from…

May 01, 2026views - 116

CYBERSECCVE

CVE-2026-41940: cPanel Bypass Risk and Mitigations

Analysis of CVE-2026-41940, a critical cPanel vulnerability with CVSS 9.8. Exploited for months, here is its impact on millions of ser…

Apr 30, 2026views - 128

VULNEXPLOIT

Linux Copy Fail Risk: The Invisible 4-Byte Root Exploit

The Linux Copy Fail vulnerability allows root escalation in 4 bytes, corrupting only RAM. Discover the impact on Kubernetes and how to…

Apr 30, 2026views - 107

cybersecEXPLOIT

SAP npm Supply Chain Attack: Malware Targets CAP Packages

The Mini Shai-Hulud campaign compromises SAP npm packages, stealing credentials and establishing persistence via AI agents. Learn how…

Apr 29, 2026views - 83

CYBERSEC

NPM Supply Chain Attack: Malware Found in Claude Code and VS Code Extensions

A new SAP npm package supply chain attack targets AI coding agent configurations. Discover how mini Shai-Hulud steals credentials and…

Apr 29, 2026views - 2.4k

CYBERSEC

Vercel Breach: The Risks of Shadow AI OAuth Exposed

The Vercel breach highlights the danger of Shadow AI integrations: how a forgotten OAuth token opened corporate doors. Here is what yo…

Apr 29, 2026views - 135

CYBERSECCRITICAL

Critical cPanel Vulnerability: Urgent Patch and Hosting Access Blocks

A critical cPanel authentication vulnerability forced providers to block access. Learn about the security risks and the importance of…

Apr 29, 2026views - 116

CYBERSEC

Entra ID Vulnerability: Patch for Agent ID Privilege Escalation

Microsoft fixed a vulnerability in Entra ID's Agent ID Administrator role. The bug allowed high-privilege service principal takeover.…

Apr 28, 2026views - 128