supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
phishing FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminal… The Record · May 22, 2026 High USphishingoauthmfa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel Former US execs plead guilty to aiding tech support scammers Two former executives of C.A. Cloud Attribution, Ltd. have pleaded guilty to aiding a years-long tech support fraud scheme that targeted individuals worldwide. The executives knowingly provided services to telemarketing… BleepingComputer · May 22, 2026 High USGBTNtech support fraudtelemarketingfraud
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
threat-intel Why Chargebacks are Just One Piece of the Fraud Puzzle This BleepingComputer article discusses the limitations of solely relying on chargeback rates to measure fraud performance. It highlights that focusing solely on chargebacks obscures a broader range of fraud impacts, inc… BleepingComputer · May 22, 2026 High account takeoverfraud detectionchargebacks
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering
threat-intel Paved With Intent: ROADtools and Nation-State Tactics in the Cloud This report details the use of ROADtools, an open-source toolkit primarily designed for red-teaming and research, by nation-state threat actors in cloud intrusions. The tool leverages legitimate Microsoft APIs to enumera… Palo Alto Unit 42 · May 22, 2026 High USentraidazureadtoken management
ransomware ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek . SecurityWeek · May 22, 2026 High
data-breach Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload The experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new and established techniques to maintain persistence in compromise… Securelist · May 22, 2026 High CVE-2018-0802
threat-intel US and Canada arrest and charge suspected Kimwolf botnet admin US and Canadian authorities have arrested Jacob Butler, an administrator of the KimWolf DDoS botnet, following a multi-national operation targeting several botnets. The botnet, which infected nearly two million devices g… BleepingComputer · May 22, 2026 High USCADEddosbotnetiot
threat-intel Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise As the 2026 FIFA World Cup approaches, scammers are exploiting fans’ desire for tickets and merchandise by creating convincing fake websites mimicking FIFA’s official channels. These sites use tactics like typosquatting… WeLiveSecurity · May 22, 2026 High phishingsocial engineeringdomain spoofing