TL;DR: The pgAdmin Development Team patched a pgAdmin 4 RCE flaw tracked as CVE-2026-17566, rated CVSS 9.4....
Credential Theft
TL;DR Veeam patched four flaws in Veeam Service Provider Console. Two are critical. One is an unauthenticated...
At a glance Malware family ACR Stealer (infostealer; linked to a rebrand of Amatera Stealer) Threat actor...
At a Glance Actor or group Unattributed threat actor; no group name published Activity type GitHub Actions...
At a glance Organization Hugging Face Data exposed A limited set of internal datasets and several service...
Malware family CrySome RAT, a .NET remote access trojan Threat actor Not named; no confirmed attribution Target...
Security Researchers Uncover Advanced Open Source Supply Chain Exploits A fresh threat report exposes an ongoing software...
Urgent Alert for DevOps Engineers Microsoft security analysts recently identified an active threat vector targeting modern software...
Arcane, the popular tool billed as “Modern Docker Management, Designed for Everyone”, has disclosed a severe security...
In a critical security alert for the PHP community, Nils Adermann, Co-Creator of Composer, has issued an...
Threat actors are increasingly abandoning loud, easily identifiable malware in favor of subtle, script-based deceptions. A new...
Microsoft’s Defender Security Research and Threat Intelligence teams have sounded the alarm on a massive, highly sophisticated...
A recent report from Kaspersky Labs reveals a disturbing surge in phishing campaigns leveraging Amazon Simple Email...
Security researchers at Varonis Threat Labs have dissected a new, all-in-one phishing platform dubbed Bluekit that is...
Securonix Threat Research has detailed a sophisticated new Python-based backdoor framework dubbed Deep#Door. This high-tech implant exemplifies...
Security researchers at Socket have uncovered a coordinated software supply chain campaign orchestrated through the GitHub account...
Security researchers have uncovered a supply-chain attack on npm targeting developers who mistakenly install the unscoped tanstack...
In the fast-moving world of AI-assisted development, a significant security oversight has been uncovered in Cursor, a...
The cybersecurity world is facing a sprawling supply chain compromise as official distribution channels for Checkmarx, a...
The Python ecosystem is reeling from a sophisticated supply chain attack targeting Xinference (Xorbits Inference), a widely...
A new and highly efficient threat has emerged on underground cybercrime networks, signaling a significant shift in...
Security researchers at StepSecurity have sounded the alarm on a compromised version of the @velora-dex/sdk package. On...