Cybersecurity

DEEP#DOOR Python Backdoor Steals Cloud Credentials

A stealthy Python backdoor called DEEP#DOOR uses a tunneling service for command-and-control to steal sensitive data, including cloud credentials and SSH keys.The malware embeds...

Linux “Copy Fail” Bug Lets Local Users Gain Root

A critical Linux flaw allows an unprivileged local user to write to a file's cache and escalate to root privileges.The vulnerability, tracked as CVE-2026-31431,...

Supply chain attack hits SAP npm packages with malware

A supply chain attack compromised four key SAP-related npm packages with credential-stealing malware on April 29, 2026.The malware, self-titled mini Shai-Hulud, steals developer and...

Critical cPanel auth flaw threatens hosting control panels

cPanel has issued urgent security updates to fix a critical authentication vulnerability.All currently supported versions of the web hosting control panel software are affected.Hosting...

CISA adds ConnectWise, Microsoft flaws to exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited software flaws to its high-threat catalog on April 29, 2026.The new entries...

Critical GitHub RCE Flaw Lets Attacker Execute Code via Git Push

A critical vulnerability (CVE-2026-3854) in GitHub allowed remote code execution via a single "git push" command.The flaw was a command injection issue where unsanitized...

Hugging Face LeRobot Flaw Allows Remote Code Execution

A critical security flaw (CVE-2026-25874) has been disclosed in Hugging Face's open-source robotics platform, LeRobot, allowing unauthenticated remote code execution.The flaw stems from unsafe...

Microsoft AI Role Flaw Allowed Identity Takeover

A privilege escalation flaw in Microsoft Entra ID's Agent ID Administrator role was patched by Microsoft on April 9, 2026.The vulnerability allowed users with...

Latest news

Chinese Hackers Target Linux With BRICKSTORM

The China-nexus cyber espionage group VerdantBamboo deployed a BSD variant of the BRICKSTORM backdoor against Linux systems.The group compromised...

Hayes Sells Worldcoin Days After Firm’s AI Bet

Arthur Hayes sold his Worldcoin (WLD) holdings days after his firm's research note touted it as a prime AI...

Trump Iran-Israel Remarks Fuel Bitcoin Market Moves

Bitcoin briefly reclaimed $64,000 this week after a recovery from lows near $59,000 but is still down over 21%...