news.mlab.sh
60 results
vulnerability

NAVTOR NavBox

A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Found…

CISA Advisories · Jun 4, 2026 Critical
data-breach

CISA Security Leak

A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA…

Schneier on Security · May 22, 2026 Critical
malware

Cross-Platform NPM Stealer, (Fri, May 22nd)

A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro…

SANS Internet Storm Center · May 22, 2026 High
threat-intel

When Identity is the Attack Path

This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c…

The Hacker News · May 21, 2026 High
threat-intel

CISA Admin Leaked AWS GovCloud Keys on Github

A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo…

Krebs on Security · May 18, 2026 High