Uncategorized

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability 2026-05-19 at 18:17 By Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability Read More »

The New Phishing Click: How OAuth Consent Bypasses MFA

The New Phishing Click: How OAuth Consent Bypasses MFA 2026-05-19 at 15:47 By In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at

The New Phishing Click: How OAuth Consent Bypasses MFA Read More »

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare 2026-05-19 at 15:47 By Drupal has issued an alert stating that it intends to release a “core security release” for all supported branches on May 20, 2026, from 5-9 p.m. UTC. “The Drupal Security Team urges you to reserve time for

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Read More »

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access 2026-05-19 at 13:31 By Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. “These vulnerabilities could

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Read More »

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer 2026-05-19 at 11:32 By Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer Read More »

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account 2026-05-19 at 09:17 By Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. “The attack affects packages tied to the npm maintainer

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account Read More »

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials 2026-05-19 at 09:17 By In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. “Every existing tag in the repository has been

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials Read More »

Meta employees told to work remotely Wednesday as company prepares to slash 10% of workforce: report

Meta employees told to work remotely Wednesday as company prepares to slash 10% of workforce: report 2026-05-19 at 00:57 By Thomas Barrabi The companywide bloodbath will take place in three waves, with impacted workers learning their fate by email at 4 a.m. local time in their region, according to an internal document obtained by Reuters.

Meta employees told to work remotely Wednesday as company prepares to slash 10% of workforce: report Read More »

Elon Musk loses lawsuit against OpenAI in unanimous verdict

Elon Musk loses lawsuit against OpenAI in unanimous verdict 2026-05-18 at 21:32 By Marc Vartabedian OAKLAND, Calif. — Jurors on Monday handed Elon Musk a loss in the landmark trial over the future of OpenAI — finding that the world’s richest person had brought his case too late.   The unanimous verdict, which the nine-member federal

Elon Musk loses lawsuit against OpenAI in unanimous verdict Read More »

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests 2026-05-18 at 21:32 By INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests Read More »

Meta employee gets dark about horror of working there as jobs bloodbath looms: ‘I tend to cry in the shower’

Meta employee gets dark about horror of working there as jobs bloodbath looms: ‘I tend to cry in the shower’ 2026-05-18 at 19:43 By Zain Khan “I definitely spend a good amount of that time sort of despondent somewhere in my house.” This article is an excerpt from Latest Technology News | New York Post

Meta employee gets dark about horror of working there as jobs bloodbath looms: ‘I tend to cry in the shower’ Read More »

MENA Region Runs First-of-its-Kind Cybercrime Operation, 201 Arrested

MENA Region Runs First-of-its-Kind Cybercrime Operation, 201 Arrested 2026-05-18 at 19:42 By The Middle East and North Africa (MENA) region, also referred to as Southwest Asia and North Africa (SWANA), managed a first-of-its-kind cybercrime operation between October 2025 and February 2026. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original

MENA Region Runs First-of-its-Kind Cybercrime Operation, 201 Arrested Read More »

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More 2026-05-18 at 19:42 By Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim:

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More Read More »

How to Reduce Phishing Exposure Before It Turns into Business Disruption

How to Reduce Phishing Exposure Before It Turns into Business Disruption 2026-05-18 at 17:23 By What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was

How to Reduce Phishing Exposure Before It Turns into Business Disruption Read More »

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement 2026-05-18 at 16:25 By During periods of economic pressure, leadership teams inevitably begin asking the same question: “Where can we cut security spend without increasing risk?” This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement Read More »

Scroll to Top