supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaig… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chaincredential theftdeveloper tools
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chain attackcredential theftpublisher badge
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
phishing FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI has issued a warning about Kali365, a phishing-as-a-service (PhaaS) platform, being used to target Microsoft 365 accounts. This platform leverages device code authentication to bypass multi-factor authentication… BleepingComputer · May 25, 2026 High USphishingoauthmfa
data-breach Oncology Institute Discloses Data Breach The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
threat-intel The Alert Firehose Finally Meets Its Match This article discusses the evolution of Network Detection and Response (NDR) systems, particularly with the integration of agentic AI. It highlights how early NDR deployments suffered from a "noisy" alert firehose due to… The Hacker News · May 25, 2026 Medium NOndraithreat intelligence
data-breach 266,000 Affected by Data Breach at Radiology Associates of Richmond Threat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on Secur… SecurityWeek · May 25, 2026 High
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
data-breach Laravel-Lang Packages Poisoned for Malware Delivery Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek . SecurityWeek · May 25, 2026 Medium
data-breach DocketWise Data Breach Impacts 143,000 Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 143,000 appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
malware Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms The Lazarus Group, a North Korean threat actor, has deployed a new memory-only remote access trojan (RAT) called RemotePE to target financial and cryptocurrency firms. This multi-stage attack chain utilizes several loade… The Hacker News · May 25, 2026 High KPremote access trojannorth koreasocial engineering
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
vulnerability Wireshark 4.6.6 Released, (Sun, May 24th) Wireshark, a popular network protocol analyzer, released version 4.6.6, addressing several issues within the software. This update includes fixes for a single vulnerability and eleven bugs, alongside an update to the Npc… SANS Internet Storm Center · May 24, 2026 Medium wiresharknetwork analysissecurity update
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
threat-intel Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes Italian authorities disrupted a sophisticated piracy operation centered around the CINEMAGOAL app, which provided unauthorized access to streaming services like Netflix and Disney+. The operation, dubbed "Tutto Chiaro,"… BleepingComputer · May 23, 2026 Medium ITFRDEpiracystreamingauthentication