Nx Console VS Code Extension Compromised to Steal Developer and Cloud Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A widely used Visual Studio Code extension was quietly turned into a credential-stealing tool in May 2026, putting millions of developers at serious risk without warning. The Nx Console extension, which has over 2.2 million installations, was …

Microsoft to Retire Teams Together Mode to Enhance Performance Improvements

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 Microsoft has announced the retirement of its “Together Mode” feature in Microsoft Teams, marking a strategic shift toward performance optimization and simplified meeting experiences. The change will take effect starting June 30, 2026, as part of the …

Hackers Compromise @antv Packages in Mini Shai-Hulud npm Attack Wave

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A sweeping supply chain attack has hit the npm ecosystem, compromising hundreds of widely used JavaScript packages tied to the @antv data visualization library. The attack, which unfolded in the early hours of May 19, 2026, injected …

CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A major security lapse has exposed highly sensitive U.S. government cloud credentials after a contractor working with the Cybersecurity and Infrastructure Security Agency (CISA) accidentally published them in a public GitHub repository. The repository, named “Private-CISA,” remained …

Hackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A compromised version of the widely used Nx Console VS Code extension was published to the Visual Studio Code Marketplace on May 18, 2026, silently targeting developer credentials, cloud infrastructure tokens, and CI/CD pipeline secrets across thousands …

Mythos Preview Builds PoC Exploits in Automated Vulnerability Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 Anthropic’s Mythos Preview security-focused AI model is crossing a critical threshold in automated vulnerability research, not just finding bugs, but chaining them together into working proof-of-concept exploits. That’s the finding from Cloudflare’s security team, which spent several …

CISA Admin Leaked AWS GovCloud Keys on Github

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said …

Hackers Actively Exploiting Critical NGINX RCE Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Hackers are wasting no time exploiting a newly disclosed critical vulnerability in NGINX, with security researchers already observing real-world attacks just days after its public release. Security researcher Patrick Garrity from VulnCheck revealed that threat actors are …

Critical n8n Vulnerabilities Expose Automation Nodes to Full RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A fresh set of critical vulnerabilities in the popular workflow automation platform n8n is raising serious security concerns, as researchers warn that attackers could chain multiple flaws to achieve full remote code execution (RCE) on affected systems. …

Linus Torvalds Says AI Bug Reports Have Made Linux Security Mailing List Unmanageable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Linus Torvalds has warned that a “continued flood” of AI‑generated bug reports is making the Linux security mailing list “almost entirely unmanageable.” The project is now tightening rules on how AI‑found issues should be reported and handled. In …