May 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations …
FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA
May 22, 2026 The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access …
Hackers Can Weaponize Lenovo Driver to Terminate EDR Processes
May 22, 2026 Hackers can weaponize a legitimately signed Lenovo driver to terminate security processes, highlighting a dangerous Bring Your Own Vulnerable Driver (BYOVD) attack vector that can bypass endpoint …
Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens
May 22, 2026 The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of developers. On May 19, npm invalidated every granular access token …
Discord Announces End-to-End Encryption by Default for Video and Voice Messages
May 22, 2026 Discord has officially rolled out end-to-end encryption (E2EE) for all voice and video communications across its platform, marking a major milestone in secure real-time communication. The feature, …
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
May 22, 2026 A sweeping automated supply chain attack codenamed “Megalodon” struck GitHub on May 18, 2026, injecting malicious CI/CD backdoors into over 5,500 repositories in less than six hours, …
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a …
Hackers Use Fake Microsoft Teams Downloads to Deploy ValleyRAT Malware
Hackers have been caught running a deceptive campaign that uses fake Microsoft Teams download websites to trick users into installing ValleyRAT, a remote access trojan capable of stealing data, logging …
TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs
May 21, 2026 A new wave of malware disguised as everyday productivity tools has been quietly spreading across the internet, stealing user credentials and giving attackers remote control of infected …
Fake Invitation Phishing Campaign Targets U.S. Organizations With Credential Theft
May 21, 2026 A large-scale phishing campaign is actively targeting U.S. organizations, using fake event invitations as bait to steal login credentials, intercept one-time passwords, or install remote access tools. …

