Advanced Phishing, SEO Poisoning, and Fake Software Installers Used to Spread MiniFast and MiniJunk V2 A state-linked Iranian cyber espionage group identified as Nimbus Manticore, also...
Hackers are actively exploiting a high-severity vulnerability in Ghost CMS to inject malicious scripts and run widespread ClickFix browser-based attacks across compromised websites. Cybersecurity researchers have...
North Korea-linked threat actors deploy advanced multi-stage RemotePE remote access trojan designed for ultra-stealthy, fileless espionage against high-value financial and cryptocurrency targets. Cybersecurity researchers have uncovered...
MAY 23, 2026 — A coordinated software supply chain attack has compromised eight packages on Packagist, the main repository for PHP dependencies, after attackers injected malicious...
SAN FRANCISCO — GitHub has launched a new set of security upgrades for npm designed to reduce software supply chain attacks, introducing two-factor authentication (2FA)-gated publishing...
A major advancement in AI-driven cybersecurity has emerged after Anthropic revealed that its experimental security initiative, Project Glasswing, has discovered more than 10,000 high- and critical-severity...
A newly disclosed critical vulnerability affecting the LiteSpeed User-End cPanel Plugin is being actively exploited by attackers, according to security warnings released by LiteSpeed Technologies. Tracked...
Drupal has released urgent security updates to address a highly critical vulnerability that could allow attackers to execute malicious code, escalate privileges, or access sensitive information...
Microsoft has dismantled a large-scale malware-signing-as-a-service (MSaaS) operation allegedly used to distribute ransomware and other malicious software under the guise of legitimate applications. The disruption, carried...
Cybersecurity Desk: A fast-moving software supply chain attack campaign known as “Mini Shai-Hulud” has compromised multiple widely used npm packages in the @antv ecosystem, raising fresh...