Must-KnowMust-KnowThe critical stories you can't miss. Thursday, August 27, 2026 PaperCut Warns of Zero-Day Flaw Exploited in NG, MF Print Management Software zero-day · vulnerability · rce Alleged TeamPCP Hackers Charged in Australia Over Trivy, Checkmarx KICS, and LiteLLM Supply Chain Attacks supply-chain · llm · github Carhartt Data Breach Exposes Information of 12.9 Million Accounts data-breach CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler RCE by Saturday rce · vulnerability · cve CISA Adds Six Actively Exploited Flaws to KEV Catalog, Including NetScaler, Linux, and SQL Server Bugs vulnerability · cve · rce Friday, August 7, 2026 Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access zero-day · sqli · vulnerability Thursday, August 6, 2026 ChainDrop: Inside a Self-Propagating npm Worm supply-chain · npm · malware Tuesday, August 4, 2026 Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks supply-chain · npm · malware Friday, July 31, 2026 CareCloud Data Breach Impacts Over 350,000 People data-breach · aws Wednesday, July 29, 2026 Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet supply-chain · npm · malware Cisco FMC Zero-Day Actively Exploited, Added to CISA KEV Catalog zero-day · vulnerability · cve OpenAI's Rogue Agent Breach Widens: JFrog Zero-Days and Stolen Credentials Hit Hugging Face and Others ai-safety · openai · zero-day · vulnerability Tuesday, July 28, 2026 Unpatched Fastjson Vulnerability Exploited in Attacks rce · vulnerability · zero-day Unpatched Fastjson Vulnerability Exploited in Attacks rce · zero-day · vulnerability Monday, July 27, 2026 Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw cve · zero-day · vulnerability Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw rce · vulnerability · zero-day · cve DentaQuest Data Breach Potentially Impacts Over 23 Million People data-breach Thursday, July 23, 2026 Data Breach Confirmed After Australian Energy Giant Origin Is Hacked data-breach Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets zero-day · phishing · vulnerability Australian Energy Giant Origin Confirms Data Breach data-breach Wednesday, July 22, 2026 Check Point Patches Actively Exploited SmartConsole Authentication Bypass zero-day · vulnerability Check Point Patches Exploited SmartConsole Zero-Day (CVE-2026-16232) zero-day · cve · vulnerability · privilege-escalation Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts data-breach CISA Orders Urgent Patch of Actively Exploited Langflow RCE Flaw rce · vulnerability · cve · llm Fourth SharePoint Vulnerability Exploited to Steal Machine Keys cve · vulnerability · privilege-escalation Monday, July 20, 2026 SonicWall SMA1000 Zero-Days Exploited for Weeks to Deploy Malware zero-day · vulnerability · malware · cve SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch zero-day · vulnerability · cve · malware Critical ServiceNow AI Platform Flaw Actively Exploited cve · rce · vulnerability · zero-day Sunday, July 19, 2026 SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access zero-day · vulnerability · privilege-escalation Friday, July 17, 2026 Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access ransomware · zero-day · vulnerability · privilege-escalation Seven Malicious npm Packages Target Vite, Use Blockchain C2 to Deliver RAT supply-chain · npm · malware Thursday, July 16, 2026 CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV rce · cve · zero-day · vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV zero-day · rce · cve · vulnerability · microsoft Wednesday, July 15, 2026 xAI Open-Sources Grok CLI After It Silently Uploaded Users' Files to the Cloud data-breach · llm · ai-safety CISA Urges Immediate Patching of Actively Exploited SharePoint Zero-Days zero-day · cve · vulnerability · rce Tuesday, July 14, 2026 SonicWall SMA1000 Zero-Days Under Active Exploitation, One Enables Command Execution zero-day · ssrf · rce · cve Two SonicWall SMA 1000 Zero-Days Under Active Exploitation zero-day · ssrf · cve · vulnerability Microsoft's Record Patch Tuesday Fixes 622 Flaws, Two Under Active Attack microsoft · cve · vulnerability · zero-day Monday, July 13, 2026 Centers Laboratory Data Breach Affects 540,000 Individuals data-breach Sunday, July 12, 2026 iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days rce · zero-day · cve · vulnerability iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days, Added to CISA KEV zero-day · cve · rce · vulnerability Friday, July 10, 2026 Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Package supply-chain · npm · github · malware Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets vulnerability · zero-day Thursday, July 9, 2026 12 Million Impacted by Data Breach at Japanese Telco KDDI data-breach · zero-day · vulnerability Wednesday, July 8, 2026 KDDI Data Breach Affects Over 12 Million People data-breach Tuesday, July 7, 2026 Accenture Confirms Breach After Hacker Offers Stolen Source Code for Sale data-breach Saturday, July 4, 2026 North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign supply-chain · npm · malware Friday, July 3, 2026 Medtronic Confirms Data Breach Affecting 3.8 Million People data-breach Thursday, July 2, 2026 FortiBleed Credential Theft Tied to INC and Lynx Ransomware Operations fortinet · ransomware · vulnerability Tuesday, June 30, 2026 Aflac Japan Data Breach Exposes 4.38 Million Policyholders data-breach CISA Confirms Active Ransomware Exploitation of Windows BlueHammer Flaw ransomware · privilege-escalation · microsoft · vulnerability CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825) zero-day · vulnerability · privilege-escalation · microsoft · ransomware Monday, June 29, 2026 Nissan, NAIC Breached via Oracle PeopleSoft Zero-Day, ShinyHunters Campaign data-breach · zero-day · vulnerability Friday, June 26, 2026 CISA Adds Actively Exploited PTC Windchill RCE Flaw to KEV Catalog vulnerability · cve · rce Miasma Supply-Chain Malware Expands to npm, GitHub Actions, and Go supply-chain · npm · github · malware First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild cve · vulnerability · rce Wednesday, June 24, 2026 Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks supply-chain · github · vulnerability · cve BeyondTrust, LastPass Impacted by Klue-Salesforce Incident supply-chain · data-breach Tuesday, June 23, 2026 Scope of Salesforce Attacks Expands as Icarus Leaks Data supply-chain · data-breach LastPass Confirms Data Breach Tied to Klue Supply Chain Attack supply-chain · data-breach FortiBleed Attackers Use Golang Sniffer to Harvest 110 Million Credentials malware · vulnerability · data-breach CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog vulnerability · cve · privilege-escalation Monday, June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack supply-chain · malware · appsec North Korean Hackers Blamed for Mastra NPM Supply Chain Attack supply-chain · npm · malware Fortinet Confirms 86,000 Working Credentials Harvested in FortiBleed Campaign data-breach · vulnerability Friday, June 19, 2026 Salesforce Disables Klue Integration After OAuth Token Abuse Exposes Customer Data supply-chain · data-breach Salesforce Disables Klue App After OAuth Token Abuse Exposes Customer Data supply-chain · data-breach Thursday, June 18, 2026 FortiBleed Leak Exposes ~74,000 Fortinet Credentials, CISA Warns data-breach · iam · fortinet 'FortiBleed' Leak Exposes Fortinet VPN Credentials for 73,000 Devices data-breach · vulnerability · cve Wednesday, June 17, 2026 144 Mastra npm Packages Compromised in Supply Chain Attack supply-chain · npm · llm · malware Tuesday, June 16, 2026 Supply Chain Attack Hits 1,500 Arch Linux AUR Packages supply-chain · malware · linux Attackers Exploit Three Fortinet FortiSandbox Flaws Including CVSS 9.1 vulnerability · cve · rce · zero-day · fortinet Monday, June 15, 2026 Trusted WordPress Plugin Scripts Tampered to Plant Hidden Admin Backdoors supply-chain · malware · appsec Friday, June 12, 2026 ShinyHunters Exploit Oracle Zero-Day to Steal Data From US Universities zero-day · data-breach · vulnerability Tuesday, June 9, 2026 Microsoft GitHub Repos Compromised to Push Password-Stealing Malware (Miasma) supply-chain · malware · github · microsoft · data-breach Chrome V8 Zero-Day CVE-2026-11645 Actively Exploited — Patch Now zero-day · vulnerability · cve · google · rce Shai-Hulud / Hades Supply Chain Campaign Hits 100+ npm and PyPI Packages supply-chain · pypi · npm · malware · data-breach Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliates zero-day · ransomware · vpn · vulnerability · cve Saturday, June 6, 2026 CVE-2026-3300: Critical Everest Forms Pro Flaw Actively Exploited for WordPress Takeover cve · vulnerability · rce · zero-day Thursday, June 4, 2026 Cisco Catalyst SD-WAN Manager Zero-Day CVE-2026-20245 Actively Exploited, No Patch Available zero-day · privilege-escalation · rce · vulnerability · cve Rust-Written IronWorm Malware Hits NPM in Credential-Propagating Supply Chain Attack supply-chain · npm · malware · credential-theft IronWorm Infostealer Hits 36 npm Packages in Supply-Chain Attack supply-chain · npm · malware · infostealer Claude Code GitHub Action Flaw Enabled Single-Issue Repository Takeover supply-chain · github · anthropic · appsec Monday, June 1, 2026 OpenAI Codex Auth Tokens Stolen via codexui-android npm Supply Chain Attack supply-chain · npm · openai · malware Friday, May 29, 2026 PAN-OS GlobalProtect CVE-2026-0257 Authentication Bypass Under Active Exploitation cve · vulnerability · zero-day · palo-alto Tuesday, May 26, 2026 CISA Emergency: Exploited LiteSpeed cPanel Plugin Zero-Day Grants Root Access zero-day · cve · vulnerability · rce Monday, May 25, 2026 Laravel-Lang Packages Poisoned to Exfiltrate CI Secrets supply-chain · malware · github · devsecops Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories supply-chain · github · malware · devsecops Saturday, May 23, 2026 LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root cve · privilege-escalation · rce · zero-day · vulnerability LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation cve · privilege-escalation · vulnerability · zero-day Friday, May 22, 2026 Megalodon GitHub Attack Injects Malicious CI/CD Workflows into 5,561 Repos supply-chain · github · malware · devsecops Grafana Codebase Stolen via TanStack Supply Chain Attack supply-chain · github · data-breach Thursday, May 21, 2026 Microsoft Defender Vulnerabilities Actively Exploited in the Wild vulnerability · cve · privilege-escalation · zero-day · microsoft Wednesday, May 20, 2026 Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack supply-chain · npm · malware GitHub Confirms 3,800 Internal Repos Breached via Malicious VS Code Extension supply-chain · github · malware · data-breach Tuesday, May 19, 2026 New Shai-Hulud Wave Compromises 600+ npm Packages in Fresh Supply Chain Hit supply-chain · npm · malware Compromised Nx Console VS Code Extension Installed Credential Stealer on 2.2M Developer Machines supply-chain · credential-stealer · malware · github Compromised Nx Console 18.95.0 Delivers Credential Stealer to 2.2M VS Code Users supply-chain · npm · credential-theft · appsec · devsecops Monday, May 18, 2026 GitHub Actions Supply Chain Attack Hijacks actions-cool/issues-helper Tags supply-chain · github · credential-theft · devsecops GitHub Actions Supply Chain Attack Redirects All Tags to Credential-Stealing Commit supply-chain · github · ci-cd · malware · credential-stealer Mini Shai-Hulud Campaign Poisons AntV npm Packages via Compromised Maintainer Account supply-chain · npm · malware · credential-stealer Microsoft Exchange Zero-Day Under Active Attack, No Patch Available zero-day · microsoft · xss · vulnerability · cve CISA Contractor Exposed AWS GovCloud Keys and Internal System Details on Public GitHub data-breach · aws · iam · github · cloud-security Grafana Source Code Stolen via Compromised GitHub Access Token supply-chain · github · data-breach Sunday, May 17, 2026 NGINX CVE-2026-42945: Heap Buffer Overflow Exploited in the Wild, RCE Risk vulnerability · cve · rce · zero-day Grafana GitHub Token Breach: Codebase Downloaded, Extortion Attempted data-breach · github · grafana · supply-chain Saturday, May 16, 2026 Funnel Builder WordPress Plugin Flaw Actively Exploited for WooCommerce Payment Skimming xss · vulnerability · appsec · zero-day Friday, May 15, 2026 node-ipc npm Package Compromised in Supply Chain Attack to Steal Credentials supply-chain · npm · malware · appsec · devsecops TanStack Supply Chain Attack Compromised Two OpenAI Employee Devices, Credentials Stolen supply-chain · npm · openai · malware · appsec TeamPCP Releases Shai-Hulud Worm Source Code, Invites Supply Chain Attacks with Monetary Rewards supply-chain · malware · npm Thursday, May 14, 2026 Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email zero-day · xss · rce · microsoft · cve Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026 zero-day · cve · vulnerability · cisco TanStack npm Supply Chain Attack Hits Multiple AI Companies supply-chain · npm · pypi · openai · appsec Monday, May 11, 2026 Official Checkmarx Jenkins AST Plugin Backdoored with Infostealer supply-chain · malware · appsec · devsecops · github Wednesday, May 6, 2026 PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal zero-day · rce · vulnerability · cve DAEMON Tools Supply Chain Attack Hits Government and Scientific Targets supply-chain · malware Tuesday, May 5, 2026 Palo Alto PAN-OS RCE Zero-Day CVE-2026-0300 Actively Exploited zero-day · rce · cve · vulnerability DAEMON Tools Official Installers Backdoored in Supply Chain Attack supply-chain · malware MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8) rce · cve · zero-day · vulnerability ScarCruft Compromises Gaming Platform to Deploy BirdCall Backdoor on Android and Windows supply-chain · malware · zero-day Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API rce · cve · zero-day · vulnerability Monday, May 4, 2026 Backdoored PyTorch Lightning Package on PyPI Delivers Credential Stealer supply-chain · pypi · malware · infostealer 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins vulnerability · cve · privilege-escalation · zero-day Saturday, May 2, 2026 Critical cPanel Flaw CVE-2026-41940 Mass-Exploited in "Sorry" Ransomware Attacks ransomware · cve · vulnerability Friday, May 1, 2026 Trellix Confirms Source Code Breach via Unauthorized Repository Access data-breach · supply-chain · appsec TeamPCP 'Mini Shai-Hulud' Supply Chain Attack Hits SAP npm Packages supply-chain · npm · malware Thursday, April 30, 2026 PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials supply-chain · pypi · malware · credential-theft Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February zero-day · vulnerability · cve · privilege-escalation Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution rce · supply-chain · npm · github · google Wednesday, April 29, 2026 SAP npm Packages Compromised in Credential-Stealing Supply Chain Attack supply-chain · npm · malware CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV zero-day · vulnerability · cve · microsoft Monday, April 27, 2026 Medtronic Breach Confirmed: ShinyHunters Claims 9 Million Records Stolen data-breach PyPI Package 'elementary-data' with 1.1M Monthly Downloads Backdoored to Steal Credentials supply-chain · pypi · malware Incomplete Windows Patch Exposes Systems to Zero-Click APT28 Attack Vector zero-day · vulnerability · microsoft · apt Thursday, April 23, 2026 Checkmarx Supply Chain Attack Compromises Bitwarden CLI and KICS Analysis Tool supply-chain · npm · cve · appsec · devsecops Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges zero-day · vulnerability · cve · microsoft · privilege-escalation Tuesday, April 21, 2026 Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day zero-day · vulnerability · cve · microsoft CVE-2026-1731: Critical Bomgar RMM RCE Actively Exploited to Spread Ransomware rce · supply-chain · ransomware · vulnerability · cve Thursday, April 16, 2026 Windows Zero-Days Leaked, Now Actively Exploited for SYSTEM Privileges zero-day · microsoft · privilege-escalation Wednesday, April 15, 2026 ShinyHunters Claims 45 Million McGraw Hill Records via Salesforce Misconfiguration data-breach · cloud-security CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited cve · vulnerability · rce · zero-day Tuesday, April 14, 2026 April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed zero-day · rce · microsoft · vulnerability · cve Monday, April 13, 2026 ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers rce · cve · zero-day · vulnerability OpenAI Rotates macOS Code-Signing Certs After North Korea-Linked Axios Supply Chain Attack supply-chain · openai · malware · github Anthropic Restricts Mythos Preview After Model Autonomously Exploits Zero-Days in Major OS and Browsers anthropic · llm · ai-safety · zero-day · vulnerability Saturday, April 11, 2026 Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621 zero-day · cve · vulnerability · appsec · rce Friday, April 10, 2026 CPUID Supply Chain Attack Poisons CPU-Z and HWMonitor Downloads supply-chain · malware Thursday, April 9, 2026 Smart Slider 3 Pro Update System Hijacked to Deliver Backdoored WordPress and Joomla Versions supply-chain · malware · wordpress · appsec Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025 zero-day · cve · vulnerability · appsec Wednesday, April 8, 2026 LiteLLM Supply Chain Attack — PyPI Packages Compromised supply-chain · pypi · llm · malware Tuesday, April 7, 2026 Claude Code Source Snippets Leaked Via Misconfigured Bucket data-breach · anthropic · cloud-security
PaperCut Warns of Zero-Day Flaw Exploited in NG, MF Print Management Software zero-day · vulnerability · rce
Alleged TeamPCP Hackers Charged in Australia Over Trivy, Checkmarx KICS, and LiteLLM Supply Chain Attacks supply-chain · llm · github
CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler RCE by Saturday rce · vulnerability · cve
CISA Adds Six Actively Exploited Flaws to KEV Catalog, Including NetScaler, Linux, and SQL Server Bugs vulnerability · cve · rce
Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access zero-day · sqli · vulnerability
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks supply-chain · npm · malware
OpenAI's Rogue Agent Breach Widens: JFrog Zero-Days and Stolen Credentials Hit Hugging Face and Others ai-safety · openai · zero-day · vulnerability
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw cve · zero-day · vulnerability
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw rce · vulnerability · zero-day · cve
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets zero-day · phishing · vulnerability
Check Point Patches Exploited SmartConsole Zero-Day (CVE-2026-16232) zero-day · cve · vulnerability · privilege-escalation
Fourth SharePoint Vulnerability Exploited to Steal Machine Keys cve · vulnerability · privilege-escalation
SonicWall SMA1000 Zero-Days Exploited for Weeks to Deploy Malware zero-day · vulnerability · malware · cve
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch zero-day · vulnerability · cve · malware
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access zero-day · vulnerability · privilege-escalation
Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access ransomware · zero-day · vulnerability · privilege-escalation
Seven Malicious npm Packages Target Vite, Use Blockchain C2 to Deliver RAT supply-chain · npm · malware
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV rce · cve · zero-day · vulnerability
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV zero-day · rce · cve · vulnerability · microsoft
xAI Open-Sources Grok CLI After It Silently Uploaded Users' Files to the Cloud data-breach · llm · ai-safety
CISA Urges Immediate Patching of Actively Exploited SharePoint Zero-Days zero-day · cve · vulnerability · rce
SonicWall SMA1000 Zero-Days Under Active Exploitation, One Enables Command Execution zero-day · ssrf · rce · cve
Microsoft's Record Patch Tuesday Fixes 622 Flaws, Two Under Active Attack microsoft · cve · vulnerability · zero-day
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days rce · zero-day · cve · vulnerability
iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days, Added to CISA KEV zero-day · cve · rce · vulnerability
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Package supply-chain · npm · github · malware
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets vulnerability · zero-day
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign supply-chain · npm · malware
FortiBleed Credential Theft Tied to INC and Lynx Ransomware Operations fortinet · ransomware · vulnerability
CISA Confirms Active Ransomware Exploitation of Windows BlueHammer Flaw ransomware · privilege-escalation · microsoft · vulnerability
CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825) zero-day · vulnerability · privilege-escalation · microsoft · ransomware
Nissan, NAIC Breached via Oracle PeopleSoft Zero-Day, ShinyHunters Campaign data-breach · zero-day · vulnerability
Miasma Supply-Chain Malware Expands to npm, GitHub Actions, and Go supply-chain · npm · github · malware
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild cve · vulnerability · rce
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks supply-chain · github · vulnerability · cve
FortiBleed Attackers Use Golang Sniffer to Harvest 110 Million Credentials malware · vulnerability · data-breach
CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog vulnerability · cve · privilege-escalation
Fortinet Confirms 86,000 Working Credentials Harvested in FortiBleed Campaign data-breach · vulnerability
Salesforce Disables Klue Integration After OAuth Token Abuse Exposes Customer Data supply-chain · data-breach
Salesforce Disables Klue App After OAuth Token Abuse Exposes Customer Data supply-chain · data-breach
'FortiBleed' Leak Exposes Fortinet VPN Credentials for 73,000 Devices data-breach · vulnerability · cve
Attackers Exploit Three Fortinet FortiSandbox Flaws Including CVSS 9.1 vulnerability · cve · rce · zero-day · fortinet
Trusted WordPress Plugin Scripts Tampered to Plant Hidden Admin Backdoors supply-chain · malware · appsec
ShinyHunters Exploit Oracle Zero-Day to Steal Data From US Universities zero-day · data-breach · vulnerability
Microsoft GitHub Repos Compromised to Push Password-Stealing Malware (Miasma) supply-chain · malware · github · microsoft · data-breach
Chrome V8 Zero-Day CVE-2026-11645 Actively Exploited — Patch Now zero-day · vulnerability · cve · google · rce
Shai-Hulud / Hades Supply Chain Campaign Hits 100+ npm and PyPI Packages supply-chain · pypi · npm · malware · data-breach
Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliates zero-day · ransomware · vpn · vulnerability · cve
CVE-2026-3300: Critical Everest Forms Pro Flaw Actively Exploited for WordPress Takeover cve · vulnerability · rce · zero-day
Cisco Catalyst SD-WAN Manager Zero-Day CVE-2026-20245 Actively Exploited, No Patch Available zero-day · privilege-escalation · rce · vulnerability · cve
Rust-Written IronWorm Malware Hits NPM in Credential-Propagating Supply Chain Attack supply-chain · npm · malware · credential-theft
IronWorm Infostealer Hits 36 npm Packages in Supply-Chain Attack supply-chain · npm · malware · infostealer
Claude Code GitHub Action Flaw Enabled Single-Issue Repository Takeover supply-chain · github · anthropic · appsec
OpenAI Codex Auth Tokens Stolen via codexui-android npm Supply Chain Attack supply-chain · npm · openai · malware
PAN-OS GlobalProtect CVE-2026-0257 Authentication Bypass Under Active Exploitation cve · vulnerability · zero-day · palo-alto
CISA Emergency: Exploited LiteSpeed cPanel Plugin Zero-Day Grants Root Access zero-day · cve · vulnerability · rce
Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories supply-chain · github · malware · devsecops
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root cve · privilege-escalation · rce · zero-day · vulnerability
LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation cve · privilege-escalation · vulnerability · zero-day
Megalodon GitHub Attack Injects Malicious CI/CD Workflows into 5,561 Repos supply-chain · github · malware · devsecops
Microsoft Defender Vulnerabilities Actively Exploited in the Wild vulnerability · cve · privilege-escalation · zero-day · microsoft
GitHub Confirms 3,800 Internal Repos Breached via Malicious VS Code Extension supply-chain · github · malware · data-breach
New Shai-Hulud Wave Compromises 600+ npm Packages in Fresh Supply Chain Hit supply-chain · npm · malware
Compromised Nx Console VS Code Extension Installed Credential Stealer on 2.2M Developer Machines supply-chain · credential-stealer · malware · github
Compromised Nx Console 18.95.0 Delivers Credential Stealer to 2.2M VS Code Users supply-chain · npm · credential-theft · appsec · devsecops
GitHub Actions Supply Chain Attack Hijacks actions-cool/issues-helper Tags supply-chain · github · credential-theft · devsecops
GitHub Actions Supply Chain Attack Redirects All Tags to Credential-Stealing Commit supply-chain · github · ci-cd · malware · credential-stealer
Mini Shai-Hulud Campaign Poisons AntV npm Packages via Compromised Maintainer Account supply-chain · npm · malware · credential-stealer
Microsoft Exchange Zero-Day Under Active Attack, No Patch Available zero-day · microsoft · xss · vulnerability · cve
CISA Contractor Exposed AWS GovCloud Keys and Internal System Details on Public GitHub data-breach · aws · iam · github · cloud-security
NGINX CVE-2026-42945: Heap Buffer Overflow Exploited in the Wild, RCE Risk vulnerability · cve · rce · zero-day
Grafana GitHub Token Breach: Codebase Downloaded, Extortion Attempted data-breach · github · grafana · supply-chain
Funnel Builder WordPress Plugin Flaw Actively Exploited for WooCommerce Payment Skimming xss · vulnerability · appsec · zero-day
node-ipc npm Package Compromised in Supply Chain Attack to Steal Credentials supply-chain · npm · malware · appsec · devsecops
TanStack Supply Chain Attack Compromised Two OpenAI Employee Devices, Credentials Stolen supply-chain · npm · openai · malware · appsec
TeamPCP Releases Shai-Hulud Worm Source Code, Invites Supply Chain Attacks with Monetary Rewards supply-chain · malware · npm
Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email zero-day · xss · rce · microsoft · cve
Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026 zero-day · cve · vulnerability · cisco
TanStack npm Supply Chain Attack Hits Multiple AI Companies supply-chain · npm · pypi · openai · appsec
Official Checkmarx Jenkins AST Plugin Backdoored with Infostealer supply-chain · malware · appsec · devsecops · github
PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal zero-day · rce · vulnerability · cve
MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8) rce · cve · zero-day · vulnerability
ScarCruft Compromises Gaming Platform to Deploy BirdCall Backdoor on Android and Windows supply-chain · malware · zero-day
Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API rce · cve · zero-day · vulnerability
Backdoored PyTorch Lightning Package on PyPI Delivers Credential Stealer supply-chain · pypi · malware · infostealer
'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins vulnerability · cve · privilege-escalation · zero-day
Critical cPanel Flaw CVE-2026-41940 Mass-Exploited in "Sorry" Ransomware Attacks ransomware · cve · vulnerability
Trellix Confirms Source Code Breach via Unauthorized Repository Access data-breach · supply-chain · appsec
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials supply-chain · pypi · malware · credential-theft
Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February zero-day · vulnerability · cve · privilege-escalation
Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution rce · supply-chain · npm · github · google
CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV zero-day · vulnerability · cve · microsoft
PyPI Package 'elementary-data' with 1.1M Monthly Downloads Backdoored to Steal Credentials supply-chain · pypi · malware
Incomplete Windows Patch Exposes Systems to Zero-Click APT28 Attack Vector zero-day · vulnerability · microsoft · apt
Checkmarx Supply Chain Attack Compromises Bitwarden CLI and KICS Analysis Tool supply-chain · npm · cve · appsec · devsecops
Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges zero-day · vulnerability · cve · microsoft · privilege-escalation
Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day zero-day · vulnerability · cve · microsoft
CVE-2026-1731: Critical Bomgar RMM RCE Actively Exploited to Spread Ransomware rce · supply-chain · ransomware · vulnerability · cve
Windows Zero-Days Leaked, Now Actively Exploited for SYSTEM Privileges zero-day · microsoft · privilege-escalation
ShinyHunters Claims 45 Million McGraw Hill Records via Salesforce Misconfiguration data-breach · cloud-security
CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited cve · vulnerability · rce · zero-day
April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed zero-day · rce · microsoft · vulnerability · cve
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers rce · cve · zero-day · vulnerability
OpenAI Rotates macOS Code-Signing Certs After North Korea-Linked Axios Supply Chain Attack supply-chain · openai · malware · github
Anthropic Restricts Mythos Preview After Model Autonomously Exploits Zero-Days in Major OS and Browsers anthropic · llm · ai-safety · zero-day · vulnerability
Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621 zero-day · cve · vulnerability · appsec · rce
Smart Slider 3 Pro Update System Hijacked to Deliver Backdoored WordPress and Joomla Versions supply-chain · malware · wordpress · appsec
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025 zero-day · cve · vulnerability · appsec