Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A sweeping automated supply chain attack codenamed “Megalodon” struck GitHub on May 18, 2026, injecting malicious CI/CD backdoors into over 5,500 repositories in less than six hours, marking one of the most aggressive GitHub Actions poisoning campaigns …

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past …

Hackers Use Fake Microsoft Teams Downloads to Deploy ValleyRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have been caught running a deceptive campaign that uses fake Microsoft Teams download websites to trick users into installing ValleyRAT, a remote access trojan capable of stealing data, logging keystrokes, and taking remote control of infected machines. The campaign, …

TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A new wave of malware disguised as everyday productivity tools has been quietly spreading across the internet, stealing user credentials and giving attackers remote control of infected systems. Researchers have tracked hundreds of campaigns tied to a …

Fake Invitation Phishing Campaign Targets U.S. Organizations With Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A large-scale phishing campaign is actively targeting U.S. organizations, using fake event invitations as bait to steal login credentials, intercept one-time passwords, or install remote access tools. The operation has been running since at least December 2025, …

Critical Chrome Vulnerabilities Enable Remote Code Execution Attacks – Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 Google has released an urgent security update for Chrome, addressing 16 vulnerabilities including two rated Critical that could allow attackers to execute arbitrary code on affected systems. The Stable channel has been updated to 148.0.7778.178/179 for Windows …

Flipper Unveils New Flipper One Modular Linux Cyberdeck

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 Flipper Devices has unveiled Flipper One, a modular Linux cyberdeck aimed at becoming a fully open, mainline-first ARM platform for hackers, researchers, and makers The company says the new device is not a successor to Flipper Zero, …

P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kubernetes clusters by breaking into Redis instances left exposed to …

GitHub Internal Repositories Breached Via Weaponized VS Code Extension

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 GitHub confirmed a significant security breach on May 18, 2026, after attackers leveraged a weaponized Visual Studio Code extension to compromise an employee’s device and exfiltrate data from the company’s internal source code repositories. The attack was …

Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, exposes a serious local privilege escalation flaw that has remained undetected for nearly nine years. Security researchers at the Qualys Threat Research Unit (TRU) revealed that the issue allows attackers to …