Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

DAEMON Tools Supply Chain Attack: Official Installers Trojanized Since April
Signed installers for DAEMON Tools Lite were caught distributing multi-stage malware for nearly a month. While thousands were infected…

MuddyWater Mimics Chaos Ransomware to Conceal Targeted Espionage Operations
A Rapid7 investigation reveals that Iranian threat actor MuddyWater impersonated a Chaos ransomware affiliate in early 2026 to mask es…

MetInfo CMS: Active RCE Exploitation Targets CVE-2026-29014
Threat actors are actively leveraging an unauthenticated RCE vulnerability (CVE-2026-29014) in MetInfo CMS. Recent activity shows a si…

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence
At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

Vimeo Data Breach: 119,200 Emails Exposed via Anodot Integration
In May 2026, the ShinyHunters threat group published a 106 GB Vimeo archive stolen via the anomaly detection platform Anodot. The leak…

Google Raises Android Bug Bounty to $15M — Chrome AI Rewards Cut
Google has overhauled its Vulnerability Reward Programs, offering up to $1.5 million for sophisticated Pixel exploits while reducing p…

OAuth Redirection Abuse: Weaponizing Trusted Domains for Government-Targeted Phishing
Microsoft has identified active phishing campaigns targeting government and public sector organizations by exploiting OAuth error flow…

Trellix Source Code Breach: The Strategic Threat of Read-Only Access
Trellix has confirmed unauthorized access to an unquantified portion of its source code repository. While the company reports no evide…

PromptMink: North Korean Hackers Weaponize AI to Poison npm Supply Chain
Researchers have uncovered 'PromptMink,' a sophisticated North Korean campaign leveraging code generated by Anthropic's Claude Opus to…

LiteLLM Exploited 36 Hours After Disclosure: Pre-Auth SQL Injection Targets AI Credentials
CVE-2026-42208 in BerriAI LiteLLM was actively exploited just 36 hours after its public disclosure. The attack targeted high-value LLM…

GitHub RCE via Git Push: An Analysis of CVE-2026-3854
CVE-2026-3854 leverages unsanitized Git push options to inject malicious metadata into the internal X-Stat header, enabling remote cod…

GitHub Enterprise Server RCE: 88% of Instances Remain Unpatched Following Public Disclosure
CVE-2026-3854 enables remote code execution on GitHub Enterprise Server via manipulated git push commands. Despite patches being avail…