A new phishing technique called VaultJacking has emerged, and it is raising serious alarms across the cybersecurity community. With just a single captured 6-digit PIN, an attacker can walk away …
AI-Generated npm Malware Accidentally Exposes Threat Actor’s Private GitHub Token
May 28, 2026 A new wave of AI-generated malware is hitting the open-source software ecosystem, and this time, the attacker made a critical mistake that gave researchers a rare inside …
Claude Opus 4.8 Released With Ability to Work as an Experienced Engineer
May 28, 2026 Anthropic has launched Claude Opus 4.8, the latest iteration of its flagship AI model, bringing sharper judgment, improved self-awareness about its own progress, and significantly extended autonomous …
Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands
A critical privilege escalation vulnerability has been discovered in OpenVPN Connect for macOS, enabling local attackers to execute arbitrary commands with elevated privileges through the application’s background service component. Tracked …
Hackers Deploy VIP Keylogger Through Phishing Emails Masquerading as Business Documents
May 28, 2026 Hackers are using deceptive phishing emails dressed up as routine business documents to spread a dangerous malware strain known as VIP Keylogger. The campaign has been active …
ClearFake Uses BSC Testnet Smart Contracts for Takedown-Resistant Command and Control
A new and dangerously clever malware campaign called ClearFake has been caught using blockchain smart contracts to run its operations, making it nearly impossible for security teams to shut it …
New Linux CIFSwitch Kernel Vulnerability Allows Attackers to Gain Root Access
May 28, 2026 A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed “CIFSwitch” enables low-privileged users to gain root access by abusing a logic flaw between the Linux kernel …
Carnival Cruise Data Breach Exposes Millions of Customers’ Personal Information
May 28, 2026 Carnival Corporation, the world’s largest cruise company and parent of Carnival Cruise Line, has begun notifying customers of a significant cybersecurity breach that exposed sensitive personal data …
Hackers Use GHOSTYNETWORKS and OMEGATECH to Host JS Malware Infrastructure
May 28, 2026 In March 2026, a wave of malicious spam emails began hitting inboxes across multiple countries and industries. Threat actors were quietly distributing a JavaScript-coded backdoor, targeting organizations …
Gitea Container Vulnerability Exposes Private Container Images to Attackers
May 28, 2026 A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self-hosted Git and …
