Cybersecurity

Supply chain attack hits SAP npm packages with malware

A supply chain attack compromised four key SAP-related npm packages with credential-stealing malware on April 29, 2026.The malware, self-titled mini Shai-Hulud, steals developer and...

Critical cPanel auth flaw threatens hosting control panels

cPanel has issued urgent security updates to fix a critical authentication vulnerability.All currently supported versions of the web hosting control panel software are affected.Hosting...

CISA adds ConnectWise, Microsoft flaws to exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited software flaws to its high-threat catalog on April 29, 2026.The new entries...

Critical GitHub RCE Flaw Lets Attacker Execute Code via Git Push

A critical vulnerability (CVE-2026-3854) in GitHub allowed remote code execution via a single "git push" command.The flaw was a command injection issue where unsanitized...

Hugging Face LeRobot Flaw Allows Remote Code Execution

A critical security flaw (CVE-2026-25874) has been disclosed in Hugging Face's open-source robotics platform, LeRobot, allowing unauthenticated remote code execution.The flaw stems from unsafe...

Microsoft AI Role Flaw Allowed Identity Takeover

A privilege escalation flaw in Microsoft Entra ID's Agent ID Administrator role was patched by Microsoft on April 9, 2026.The vulnerability allowed users with...

Checkmarx Data Leaked on Dark Web Following Attack

Checkmarx confirms stolen data from its GitHub repository was published on the dark web.The company states no customer data was stored in the compromised...

CISA Adds 4 Exploited Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on April 24, 2026.The flaws...

Latest news

$3.7B in Stablecoins Frozen by Censorship

Tether and Circle have frozen approximately $3.7 billion in stablecoins on the Ethereum and Tron blockchains over six years.The...

Russian APT’s 2025 Onslaught: Malware Evolves Against Ukraine

The Russian-linked Gamaredon APT group executed 35 spear-phishing campaigns in 2025, primarily targeting Ukrainian government and military entities.Their arsenal...

Bernstein Sees Entry Point As Nvidia Stock Hits $190

Analysts at Bernstein have reiterated a 'buy' rating for NVIDIA stock, suggesting the current dip below $190 could be...