May 20, 2026 A large-scale ad fraud operation called Trapdoor has been discovered targeting Android users through 455 malicious apps, quietly generating fake ad clicks and draining real advertising budgets …
DevilNFC Android Malware Uses Kiosk Mode to Trap Victims During NFC Relay Attacks
A dangerous new Android malware called DevilNFC has emerged, combining NFC relay attacks with a Kiosk Mode trap that locks victims inside a fake banking screen until their card data …
PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released
May 20, 2026 A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Discovered by Aaron Esau of the V12 security team, the …
How to Close the Most Expensive Gap in Your SOC
May 20, 2026 Close Your SOC’s Most Expensive Gap There is a quiet gap inside many SOCs. It sits between the moment Tier 1 says “this should be escalated” and …
Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability
May 20, 2026 Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing …
New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code
May 20, 2026 A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in …
GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device
May 20, 2026 GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in …
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability
A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly …
ShinyHunters Claims Credit for Cyber-Attack on Online Learning Management System
May 20, 2026 A recent cyberattack targeting an online Learning Management System (LMS) has been attributed to the notorious cybercriminal group ShinyHunters. The incident caused widespread service disruptions affecting educational …
GitHub Source Code Breach – TeamPCP Claims Access to Internal Source Code
May 20, 2026 A notorious threat actor operating under the alias TeamPCP claims to have breached GitHub’s internal systems, allegedly exfiltrating proprietary organization data and source code. The attackers are offering the …
