May 12, 2026 Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to …
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack
May 12, 2026 A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. …
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
May 12, 2026 In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 …
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes
May 12, 2026 A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machines …
Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers
May 12, 2026 A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8, …
84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials
May 12, 2026 A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, …
Popular Go Library fsnotify Raises Supply Chain Alarms After Maintainer Access Changes
May 11, 2026 A widely used Go library called fsnotify has found itself at the center of a supply chain security scare after a sudden change in maintainer access triggered …
Google Warns of Hackers Using AI to Create Working Zero-Day Exploit
Google Threat Intelligence Group recently published an alarming report detailing the rapid industrialization of generative artificial intelligence in adversarial workflows. The most significant finding reveals that a cybercriminal syndicate successfully …
Hackers Use PlugX-Like DLL Sideloading Chain in Fake Claude Malware Campaign
May 11, 2026 Cybercriminals are getting creative with how they lure victims into downloading malware, and a new campaign involving a fake version of Anthropic’s Claude AI assistant is raising …
Hackers Use Fake DeepSeek TUI GitHub Repositories to Deliver Malware
May 11, 2026 Hackers are once again targeting developers and AI enthusiasts by impersonating popular open-source tools on GitHub. This time, the target is DeepSeek TUI, a legitimate terminal-based intelligent …
