May 21, 2026 A new wave of malware disguised as everyday productivity tools has been quietly spreading across the internet, stealing user credentials and giving attackers remote control of infected …
Fake Invitation Phishing Campaign Targets U.S. Organizations With Credential Theft
May 21, 2026 A large-scale phishing campaign is actively targeting U.S. organizations, using fake event invitations as bait to steal login credentials, intercept one-time passwords, or install remote access tools. …
Critical Chrome Vulnerabilities Enable Remote Code Execution Attacks – Patch Now!
May 21, 2026 Google has released an urgent security update for Chrome, addressing 16 vulnerabilities including two rated Critical that could allow attackers to execute arbitrary code on affected systems. …
Flipper Unveils New Flipper One Modular Linux Cyberdeck
May 21, 2026 Flipper Devices has unveiled Flipper One, a modular Linux cyberdeck aimed at becoming a fully open, mainline-first ARM platform for hackers, researchers, and makers The company says …
P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances
May 21, 2026 A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising …
GitHub Internal Repositories Breached Via Weaponized VS Code Extension
May 21, 2026 GitHub confirmed a significant security breach on May 18, 2026, after attackers leveraged a weaponized Visual Studio Code extension to compromise an employee’s device and exfiltrate data …
Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, exposes a serious local privilege escalation flaw that has remained undetected for nearly nine years. Security researchers at the Qualys Threat …
New Microsoft Defender 0‑Days Actively Exploited in the Wild
May 21, 2026 Two newly disclosed Microsoft Defender vulnerabilities are being actively exploited in the wild, enabling local attackers to elevate privileges to SYSTEM and potentially disrupt endpoint protection across …
New NGINX 0-Day RCE “nginx-poolslip” Affects Millions of NGINX Servers
May 21, 2026 A newly disclosed zero-day remote code execution (RCE) vulnerability, dubbed nginx-poolslip, has been identified in NGINX version 1.31.0, the latest stable release of the widely deployed web …
WantToCry Ransomware Abuses SMB Services to Remotely Encrypt Files
May 21, 2026 A ransomware strain called WantToCry has been targeting businesses by abusing a widely used file-sharing protocol to encrypt files without dropping any malware on the victim’s system. …
