April 30, 2026 A new open-source project called CVE MCP Server is redefining how security teams triage vulnerabilities, transforming Anthropic’s Claude AI into a fully capable security analyst by giving …
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent
April 30, 2026 A new threat has quietly taken root in the software development world, using an AI coding assistant as an unknowing participant in a supply chain attack. A …
Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise
A high-severity access-control vulnerability (CVSS 8.2) in Cursor, a widely used AI-powered coding environment. The flaw uncovered by LayerX has allowed any installed extension to access a developer’s API keys …
Linux Kernel 0-Day “Copy Fail” Roots Every Major Distribution Since 2017
April 30, 2026 A critical zero-day vulnerability in the Linux kernel has been publicly disclosed, enabling any unprivileged local user to obtain root access on virtually every major Linux distribution …
SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets
April 29, 2026 A new supply chain attack dubbed “mini Shai Hulud” has compromised four SAP-related npm packages by injecting malicious preinstall scripts that silently execute during dependency installation, targeting …
Lazarus Hackers Attacking macOS Users With ‘Mach-O Man’ Malware Kit
April 29, 2026 Mach-O Man Malware Targets macOS Crypto Executives North Korea’s state-sponsored Lazarus Group has unleashed a newly identified, modular macOS malware kit dubbed “Mach-O Man” a sophisticated, four-stage …
Brinker Introduces a Novel Approach to Deepfake Detection
April 29, 2026 WILMINGTON, Delaware, April 29th, 2026, CyberNewswire Malicious intent-based deepfake detection shifts the focus from purely technical analysis to real-world risk and impact Brinker, recently named “Narrative Intelligence …
Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection
April 29, 2026 A dangerous infostealer malware called LofyStealer is actively targeting Minecraft players by disguising itself as a game cheat tool named “Slinky.” The malware runs a two-stage attack …
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
April 29, 2026 A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware …
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group …
