Cybersecurity

New npm Malware Steals Claude AI User Data

A new malicious npm package, "mouse5212-super-formatter," steals files from the Claude AI tool's dedicated upload directory.The malware uploads stolen data to a threat actor-controlled...

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named GlassWorm on May 27, 2026.The botnet used trojanized VS Code...

India’s CERT Issues 12-Hour Patch Order

The Indian Computer Emergency Response Team (CERT-In) mandates a 12-hour patch deadline for critical vulnerabilities where feasible.The directive responds to threat actors increasingly using...

Digital Knowledge LMS Zero-Day Deploys Malware

A critical vulnerability (CVE-2026-5426) in the Japanese LMS Digital Knowledge KnowledgeDeliver allowed unauthenticated remote code execution.Attackers exploited this flaw as a zero-day to deploy...

Ghost CMS Flaw Fuels Widespread ClickFix Malware

A critical SQL injection flaw (CVE-2026-26980) in Ghost CMS is being actively exploited to hijack website articles.Attackers have compromised over 700 legitimate websites across...

TrapDoor Malware Targets npm, PyPI, Crates.io in Supply Chain Attack

A coordinated supply chain attack, codenamed TrapDoor, has deployed malware across three major developer platforms: npm, PyPI, and Crates.io.The campaign targets crypto, DeFi, Solana,...

npm Staged Publishing Requires Human Approval

GitHub has introduced mandatory two-factor approval for npm package releases to combat software supply chain attacks.A new "staged publishing" feature requires human maintainers to...

Criminal VPN Service Dismantled in Global Operation

A criminal VPN service used by at least 25 ransomware groups was dismantled in a May 2026 global operation.The service, First VPN, advertised anonymity...

Latest news

Red Hat npm packages hit by self-propagating Miasma worm

A new supply chain attack campaign called Miasma has compromised multiple official @redhat-cloud-services npm packages.The malware steals credentials and...

Oil Surges as US, Iran Cut Talks Over Hormuz

Brent crude oil surged 5% to over $96 a barrel after Iran ended peace talks and threatened to close...

Florida Files “First-In-Nation” Lawsuit Against OpenAI

Florida AG James Uthmeier filed what is described as the first state-led lawsuit against OpenAI and CEO Sam Altman...