// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

DAEMON Tools Supply Chain Attack: Official Installers Trojanized Since April

Signed installers for DAEMON Tools Lite were caught distributing multi-stage malware for nearly a month. While thousands were infected…

May 06, 2026views - 230

CYBERSEC

MuddyWater Mimics Chaos Ransomware to Conceal Targeted Espionage Operations

A Rapid7 investigation reveals that Iranian threat actor MuddyWater impersonated a Chaos ransomware affiliate in early 2026 to mask es…

May 06, 2026views - 191

CYBERSECCRITICAL

MetInfo CMS: Active RCE Exploitation Targets CVE-2026-29014

Threat actors are actively leveraging an unauthenticated RCE vulnerability (CVE-2026-29014) in MetInfo CMS. Recent activity shows a si…

May 06, 2026views - 196

CYBERSEC

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence

At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

May 06, 2026views - 151

CYBERSEC

Vimeo Data Breach: 119,200 Emails Exposed via Anodot Integration

In May 2026, the ShinyHunters threat group published a 106 GB Vimeo archive stolen via the anomaly detection platform Anodot. The leak…

May 05, 2026views - 167

CYBERSECEXPLOIT

Google Raises Android Bug Bounty to $15M — Chrome AI Rewards Cut

Google has overhauled its Vulnerability Reward Programs, offering up to $1.5 million for sophisticated Pixel exploits while reducing p…

May 05, 2026views - 235

CYBERSEC

OAuth Redirection Abuse: Weaponizing Trusted Domains for Government-Targeted Phishing

Microsoft has identified active phishing campaigns targeting government and public sector organizations by exploiting OAuth error flow…

May 05, 2026views - 149

CYBERSEC

Trellix Source Code Breach: The Strategic Threat of Read-Only Access

Trellix has confirmed unauthorized access to an unquantified portion of its source code repository. While the company reports no evide…

May 05, 2026views - 198

CYBERSEC

PromptMink: North Korean Hackers Weaponize AI to Poison npm Supply Chain

Researchers have uncovered 'PromptMink,' a sophisticated North Korean campaign leveraging code generated by Anthropic's Claude Opus to…

May 04, 2026views - 239

CYBERSECEXPLOIT

LiteLLM Exploited 36 Hours After Disclosure: Pre-Auth SQL Injection Targets AI Credentials

CVE-2026-42208 in BerriAI LiteLLM was actively exploited just 36 hours after its public disclosure. The attack targeted high-value LLM…

May 02, 2026views - 178

CYBERSECCRITICAL

GitHub RCE via Git Push: An Analysis of CVE-2026-3854

CVE-2026-3854 leverages unsanitized Git push options to inject malicious metadata into the internal X-Stat header, enabling remote cod…

May 01, 2026views - 180

CYBERSECCRITICAL

GitHub Enterprise Server RCE: 88% of Instances Remain Unpatched Following Public Disclosure

CVE-2026-3854 enables remote code execution on GitHub Enterprise Server via manipulated git push commands. Despite patches being avail…

May 01, 2026views - 145