Operation BlueDash Uses Fake Teams Updates for Remote Access
Operation BlueDash turns a secure-document email into a fake Teams update that…
CVE-2026-16812 Exploited in VeloCloud Orchestrator
Arista confirms active exploitation of CVE-2026-16812 in VeloCloud Orchestrator On-Prem. Check affected…
OpenAI Agent Hacked Hugging Face—and Went Unnoticed for Days
An OpenAI evaluation agent reached Hugging Face production while pursuing benchmark answers.…
npm Staged Publishing: What Maintainers Should Change Now
npm CLI 11.15.0 adds staged publishing and new install-source controls. Here is…
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited for Root Scripts
LiteSpeed says CVE-2026-48172 is being actively exploited in its user-end cPanel plugin.…
Packagist Postinstall Malware: What Developers Should Check
A Packagist and GitHub supply-chain campaign used malicious postinstall hooks to fetch…
West Pharmaceutical Cyberattack Stole Data and Encrypted Systems
West Pharmaceutical disclosed a material cyberattack involving data exfiltration, encrypted systems, and…
Polish Water Plants Hit by ICS Breaches, ABW Says
Poland's ABW says hackers breached control systems at five water treatment plants,…
cPanel WHM Patches File Read and Code Injection Bugs
cPanel patched three WHM and WP Squared vulnerabilities affecting server control paths,…
Canvas Breach: Login Portals Defaced in Extortion Attack
Instructure says a Canvas incident exposed names, emails, student IDs, and user…
MuddyWater Uses Microsoft Teams Phishing in Chaos Ransomware Masquerade
Rapid7 says MuddyWater used Microsoft Teams social engineering, remote tools, stolen credentials,…
Chinese Hackers Used Claude AI to Automate 90% of Cyber Espionage Campaign
Chinese cyber spies automated 90% of their attack campaign using Claude AI.…
