Hackers Compromise 170 npm Packages to Steal GitHub, npm, AWS, and Kubernetes Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A sprawling supply chain attack has put software developers worldwide on high alert after hackers compromised more than 170 npm packages and two PyPI packages in a coordinated credential theft campaign. The infected packages are collectively downloaded …

Amazon Quick Bug Exposed AI Chat Agents to Users Blocked by Custom Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Imagine locking your organization’s sensitive data behind a heavy vault door, only to realize the locking mechanism is entirely missing. Security researchers at Fog Security recently uncovered a severe authorization bypass in Amazon Quick’s AI Chat Agents. …

New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical vulnerability in the widely used Exim mail server allows unauthenticated attackers to execute arbitrary code and fully compromise exposed servers. Federico Kirschbaum, head of the Security Lab at XBOW, discovered and reported the issue, which …

Dell Support assist Updates Forces Windows Systems to BSOD Loop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A faulty update to Dell’s SupportAssist Remediation service is sending thousands of Dell and Alienware laptop users into endless Blue Screen of Death (BSOD) loops, with systems crashing every 30 minutes and displaying the dreaded CRITICAL_PROCESS_DIED stop …

Microsoft Research Shows AI Can Generate Realistic Command Lines and Process Telemetry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Artificial intelligence is now capable of generating attack telemetry that looks and behaves like the real thing, and that is changing how security teams think about testing their defenses. In new work, Microsoft researchers show that large …

Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Threat actors are constantly hunting for infrastructure weaknesses, and a newly discovered batch of vulnerabilities in GitLab just handed them a dangerous roadmap. On May 13, 2026, GitLab rolled out emergency security updates to address multiple high-severity …

Lyrie.ai Launches the Global Identity Standard for the AI Agent Age & Anthropic’s Cyber Verification Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 DUBAI, UAE — May 11, 2026 — As the internet transitions from a playground of chatbots to a workforce of autonomous agents, the question isn’t just what AI can do—it’s who the AI is. Today, OTT Cybersecurity LLC officially launched …

OpenAI Hit with Class-Action Privacy Lawsuit for Sharing ChatGPT Data with Google and Meta

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 OpenAI Global LLC is facing a new class‑action complaint in the Southern District of California that accuses the company of quietly wiring its ChatGPT web interface with Meta’s Facebook Pixel and Google Analytics, turning highly sensitive chatbot …

Windows DNS Client Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly disclosed vulnerability in the Microsoft Windows DNS Client could let attackers silently execute malicious code across enterprise networks, exposing a massive attack surface. Officially designated as CVE-2026-41096, this critical security flaw carries a severe CVSS …

Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution …