• Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

    Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

    Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. “Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred…

    Read More

  • Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories. “After the initial assessment,…

    Read More

  • GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories

    GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories

    GitHub on Tuesday said it’s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform’s source code and internal organizations for sale on a cybercrime forum. “While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’…

    Read More

  • May 19 Primary Election: Preliminary results for Hood River and Wasco counties

    May 19 Primary Election: Preliminary results for Hood River and Wasco counties

    Free news: preliminary results of the May 19 Primary Election as of 8 p.m.

    Read More

  • Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

    Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

    Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN’s Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud. “Users

    Read More

  • DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

    DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

    Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that…

    Read More

  • The New Phishing Click: How OAuth Consent Bypasses MFA

    The New Phishing Click: How OAuth Consent Bypasses MFA

    In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had…

    Read More

  • SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

    SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

    Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. “These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the…

    Read More

  • Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

    Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2…

    Read More

  • GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

    GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

    In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. “Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action’s normal…

    Read More