May 20, 2026 GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in …
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability
A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly …
ShinyHunters Claims Credit for Cyber-Attack on Online Learning Management System
May 20, 2026 A recent cyberattack targeting an online Learning Management System (LMS) has been attributed to the notorious cybercriminal group ShinyHunters. The incident caused widespread service disruptions affecting educational …
GitHub Source Code Breach – TeamPCP Claims Access to Internal Source Code
May 20, 2026 A notorious threat actor operating under the alias TeamPCP claims to have breached GitHub’s internal systems, allegedly exfiltrating proprietary organization data and source code. The attackers are offering the …
UAC-0184 Malware Chain Uses bitsadmin and HTA Files for Gated Payload Delivery
May 19, 2026 A newly documented attack chain linked to the threat group UAC-0184 has been observed using Windows’ built-in bitsadmin tool and HTA files to sneak malicious payloads onto …
macOS Malware Installs Fake Google Software Update LaunchAgent for Persistence
May 19, 2026 macOS users are facing a new and sophisticated threat as a variant of the SHub infostealer malware, dubbed “Reaper,” has been observed deploying a fake Google Software …
The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Attacks
May 19, 2026 A ransomware group called The Gentlemen has been quietly building one of the most aggressive cybercriminal operations seen in recent years. Emerging publicly in the second half …
Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials
May 19, 2026 North Korea-linked hackers are at it again, and this time they are casting a wide net. The Kimsuky threat group, a well-known cyber espionage unit with ties …
Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
May 19, 2026 A wave of well-crafted malware is quietly draining cryptocurrency from users across the globe, and the attackers behind it have gone to great lengths to stay hidden. …
DirtyDecrypt Linux Kernel Vulnerability PoC Exploit Code Released
May 19, 2026 A working proof-of-concept (PoC) exploit for a high-severity Linux kernel local privilege escalation vulnerability dubbed DirtyDecrypt, also tracked as DirtyCBC, enables local attackers to gain full root access on …
