threat-intel Why Chargebacks are Just One Piece of the Fraud Puzzle This BleepingComputer article discusses the limitations of solely relying on chargeback rates to measure fraud performance. It highlights that focusing solely on chargebacks obscures a broader range of fraud impacts, inc… BleepingComputer · May 22, 2026 High account takeoverfraud detectionchargebacks
threat-intel When Identity is the Attack Path This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c… The Hacker News · May 21, 2026 High USidentitycredentialspermissions
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
supply-chain Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem This article highlights a significant shift in cyberattack tactics, moving away from traditional phishing and towards a supply chain attack leveraging AI-generated lookalike domains and compromised third-party scripts. T… The Hacker News · May 20, 2026 Critical USsupply-chainbrowserai
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
vulnerability Siemens Solid Edge Siemens Solid Edge SE2026 is affected by two file parsing vulnerabilities that could allow an attacker to crash the application or execute arbitrary code when processing specially crafted PAR files. Siemens has released… CISA Advisories · May 14, 2026 High CVE-2026-44411CVE-2026-44412DEbuffer overflowfile parsingstack overflow
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr