data-breach Lithuania investigates theft of 600,000 state registry records by foreign actor Lithuania is investigating a significant data breach affecting its state registry systems, resulting in the theft of approximately 600,000 records containing personal and property information. The breach exploited compro… The Record · May 26, 2026 High LTRUBYdata breachregistrycyberattack
threat-intel CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks CERT-In has mandated a 12-hour patching window for critical internet-facing vulnerabilities, driven by the increasing use of AI by threat actors to automate attacks. This response is intended to address the accelerated a… The Hacker News · May 26, 2026 High INaicybersecurityvulnerability
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
supply-chain Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility This article highlights a growing cybersecurity crisis driven by the rapid proliferation of vulnerabilities and the decreasing time it takes for attackers to exploit them. The analysis, primarily based on a Black Kite re… SecurityWeek · May 21, 2026 High USsupply chainvulnerabilityai
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud
threat-intel AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop This SecurityWeek article highlights a significant shift in app security driven by the rapid adoption of AI by cybercriminals. The report from Digital.ai indicates a dramatic increase in attacks against apps, moving from… SecurityWeek · May 20, 2026 High USGBaiagentic aiapp security