Microsoft has strongly criticized the public disclosure of multiple zero-day vulnerabilities affecting Windows systems, reaffirming its support for Coordinated Vulnerability Disclosure (CVD) and warning that premature...
A high-severity vulnerability in the KnowledgeDeliver LMS platform has been actively exploited as a zero-day to deliver web shells and post-exploitation malware, including Cobalt Strike Beacon....
Advanced Phishing, SEO Poisoning, and Fake Software Installers Used to Spread MiniFast and MiniJunk V2 A state-linked Iranian cyber espionage group identified as Nimbus Manticore, also...
From long-ignored Linux vulnerabilities to AI-driven phishing campaigns and supply chain compromises, this week’s cybersecurity landscape highlights one clear trend: attackers are moving faster than defenders...
MAY 23, 2026 — A coordinated software supply chain attack has compromised eight packages on Packagist, the main repository for PHP dependencies, after attackers injected malicious...
SAN FRANCISCO — GitHub has launched a new set of security upgrades for npm designed to reduce software supply chain attacks, introducing two-factor authentication (2FA)-gated publishing...
A serious software supply chain attack has been uncovered targeting multiple PHP packages within the Laravel-Lang ecosystem, raising alarm across the developer and cybersecurity communities. The...
A major advancement in AI-driven cybersecurity has emerged after Anthropic revealed that its experimental security initiative, Project Glasswing, has discovered more than 10,000 high- and critical-severity...
A critical security vulnerability affecting Drupal Core is now being actively exploited across the internet, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add...
A newly disclosed critical vulnerability affecting the LiteSpeed User-End cPanel Plugin is being actively exploited by attackers, according to security warnings released by LiteSpeed Technologies. Tracked...