threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant supply chain attack orchestrated by TeamPCP targeting npm packages. The rapid exploitation of vulnera… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
threat-intel Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Multiple vendors, including Ivanti, Fortinet, SAP, and VMware, have released security patches to address critical vulnerabilities across their products. These vulnerabilities include remote code execution, SQL injection,… The Hacker News · May 18, 2026 Critical CVE-2026-8043CVE-2026-44277CVE-2026-26083USUKremote code executionsql injectionprivilege escalation