• PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials

    PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials

    In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both of which were published on April 30, 2026. The campaign is…

    Read More

  • ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

    ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

    The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to be online. Security is always a moving target.…

    Read More

  • New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

    New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

    Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persistent access and harvest a wide range of sensitive information from compromised hosts. “The intrusion chain begins with execution of a batch script (‘install_obf.bat’) that disables Windows security controls, dynamically extracts an

    Read More

  • New Linux ‘Copy Fail’ Vulnerability Enables Root Access on Major Distributions

    New Linux ‘Copy Fail’ Vulnerability Enables Root Access on Major Distributions

    Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability tracked as CVE-2026-31431 (CVSS score: 7.8) has been codenamed Copy Fail by Xint.io and Theori. “An unprivileged local user can write four controlled bytes into the page cache of…

    Read More

  • Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

    Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

    Google has addressed a maximum severity security flaw in Gemini CLI — the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow — that could have allowed attackers to execute arbitrary commands on host systems. “The vulnerability allowed an unprivileged external attacker to force their own malicious content to load as Gemini configuration,”

    Read More

  • SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

    SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

    Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP’s JavaScript and cloud application

    Read More

  • New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

    New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

    Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic’s Claude Opus large language model (LLM). The package in question is “@validate-sdk/v2,” which is listed on npm as a utility software development kit (SDK) for hashing, validation, encoding/decoding, and secure random generation. However,…

    Read More

  • Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

    Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

    In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren’t just talking about AI writing better phishing emails anymore. We’re talking about autonomous agents mapping Active Directory and seizing Domain Admin credentials in minutes. The…

    Read More

  • What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)

    What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)

    Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities closed. The dashboards are bursting with green. Then someone in a leadership meeting asks: “So, are we actually safer now?” Crickets. The room goes quiet because an honest answer requires context – which is something that patch counts…

    Read More

  • Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

    Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

    cPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the control panel software. The problem affects all currently supported versions, according to an alert released by cPanel on Tuesday. The issue has been addressed in the following versions – 11.110.0.97 11.118.0.63…

    Read More