Security · Top stories
200 GitHub Repositories Used to Spread Malware in 'Operation Muck and Load'
A threat actor has leveraged 200 GitHub repositories to distribute malware in 'Operation Muck and Load'. The campaign uses a deceptive Go module posing as a DNS scanner, distributing over 700 malicious variants since January 2023 to execute spyware, trojans, and other malware. This highlights significant risks in software supply chain security.
Six Vulnerabilities Found in U-Boot Bootloader Threaten Device Security at Boot
Six vulnerabilities in the U-Boot bootloader, used in devices from routers to servers, have been identified. These flaws enable attackers to execute arbitrary code or crash devices during boot, compromising security before the operating system verifies software. This poses significant risks due to U-Boot's widespread deployment in various embedded systems.
Armenian Man Pleads Guilty to Involvement in Ryuk Ransomware Attacks
Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in the US to charges related to deploying Ryuk ransomware. Extradited from Ukraine, Vardanyan facilitated attacks from November 2019 to April 2020, securing approximately $15 million in ransoms. His case underscores ongoing cybersecurity threats impacting various sectors.
Injective SDK npm Package Compromised to Steal Cryptocurrency Keys
A version of the Injective SDK npm package was compromised, leading to the theft of cryptocurrency wallet private keys via a malicious version. Hackers accessed Injective Labs' GitHub to publish the harmful package, affecting developers in the decentralized finance space.
Supreme Court Ruling on Location Data May Impact Automated License Plate Cameras
The Supreme Court's decision in Chatrie v. United States mandates warrants for cellphone location data, potentially affecting the use of automated license plate readers (ALPRs) like those used by Flock Safety. This could impose legal constraints on current law enforcement practices utilizing widespread ALPR networks without warrants. The case reflects broader privacy concerns about surveillance technologies and Fourth Amendment rights.
Dutch Police Probe Local Hackers in Odido Telecom Data Breach
The Dutch police are investigating local hackers in the February Odido data breach affecting 6.2 million customers. A suspect impersonated an Odido IT employee, facilitating unauthorized access through a customer contact system. Authorities are requesting public assistance to identify the caller.
AI Agents Expose Gaps in Enterprise Identity Governance Systems
AI agents are increasing machine identities in enterprises, highlighting gaps in identity governance. Traditional identity access management (IAM) systems were not designed for autonomous AI, often causing security risks due to over-privileged access. Addressing this issue is critical for secure enterprise operations.
GigaWiper: New Sophisticated Windows Backdoor with Destructive Capabilities
Microsoft has uncovered GigaWiper, a sophisticated malware targeting Windows machines. This backdoor combines older destructive programs to offer disk wiping, fake ransomware, and spyware functions, showcasing a shift in wiper malware to extortion activities. Its likely connections to cyber threats against Israeli organizations highlight the need for vigilance and strong cyber defenses.
UK Unveils AI-Driven 'Cyber Shield' for Enhanced National Cybersecurity
The UK announced the Cyber Shield initiative to improve national cybersecurity through agentic AI systems. The initiative, led by the National Cyber Security Centre, focuses on countering advanced threats that exploit AI to rapidly identify vulnerabilities. This collaboration with academia and industry aims to hardwire AI advancements into national security defenses against increasingly sophisticated cyber threats.
Mount Royal University Hit by Ransomware Attack, Data Stolen and Deleted
Mount Royal University in Calgary experienced a ransomware attack that led to the theft and deletion of student and employee data from its 'H drive' file storage systems. The CMD Organization, the group responsible for the attack, demanded a $1.9 million ransom for over 10 terabytes of data. This incident, impacting various university systems, emphasizes the ongoing risk of ransomware threats in the education sector.
AssuranceAmerica Data Breach Exposes 6.9 Million Driver Records
AssuranceAmerica has suffered a data breach affecting 6.9 million individuals' driver’s license information, names, and contact details. Discovered on March 17, the breach is the largest known exposure of U.S. driver's license data this year, significantly impacting personal data security and prompting potential fraud concerns.
Suspected China-Linked Hackers Target Roundcube Vulnerabilities in U.S. and Canadian Universities
A China-linked threat group named UNK_MassTraction has exploited a critical Roundcube webmail vulnerability to infiltrate physics and engineering departments in U.S. and Canadian universities, stealing credentials and deploying malware. The targeted campaign, identified by Proofpoint, has significant implications for national security and academic research.
Accenture Confirms Data Breach as Hacker Offers Source Code for Sale
Accenture has confirmed a data breach involving the theft of 35 GB of sensitive data, including source code and Azure credentials. A hacker is offering the data for sale, raising concerns about potential future exploitation. Accenture stated there is no impact on their operations and they have addressed the breach's source.
Ubiquiti Releases Critical Security Patch Updates for UniFi OS Suite
Ubiquiti has issued patches for seven critical vulnerabilities in its UniFi OS software suite, affecting applications like UniFi Connect, Talk, Access, and Protect. These security flaws, including CVE-2026-50746, allow command injection and privilege escalation attacks. Users are strongly advised to update their systems to secure versions to mitigate potential breaches.
Spanish Police Arrest Suspected Member of Pro-Russian Hacktivist Groups
Spanish authorities arrested a man in Palencia linked to pro-Russian hacktivist groups CARR and Z-Pentest following an FBI tip. The suspect is accused of aiding a hacker's escape and supporting cyber activities against Ukraine. The arrest could impact international investigations into cyber threats.
Google Patches Critical Flaw in Dialogflow CX Chatbot Platform
Google has patched a critical vulnerability in its Dialogflow CX platform that could have allowed attackers with specific permissions to compromise multiple chatbots within a single Google Cloud project. Dubbed 'Rogue Agent' by Varonis, the issue involved the execution of shared Code Blocks, which allowed unauthorized data access and message manipulation. No attacks exploiting this flaw were reported, and it was primarily a risk from insiders or compromised accounts.
Git Commit Signature Malleability Allows Tampered Verified Commit Hashes
Research has revealed Git commit hash malleability, enabling distinct commits with identical content, metadata, and valid signatures. The "hash chain malleability" flaw impacts systems relying on commit hash integrity, like dependency management and reproducible builds, leading to potential integrity risks.
Apple's Antitrust Appeal Over EU 'Gatekeeper' Status Rejected
Apple's legal challenge against its designation as a 'gatekeeper' under the EU's Digital Markets Act has been rejected. The ruling demands Apple allows interoperability with rival services and may affect its business model in Europe by enforcing fairer competition.
Union County, Ohio Paid $1 Million to Cyber Group to Prevent Data Leak
Union County, Ohio paid $1 million to Kairos to prevent the release of stolen data after a May 2025 breach. This marks a significant data extortion case as there was no ransomware involved, emphasizing vulnerabilities in government data security without direct system lock-ups.
Cordyceps Vulnerability Exposes Over 300 GitHub Repositories to Supply-Chain Attacks
Researchers from Novee Security have identified a CI/CD vulnerability, named Cordyceps, affecting over 300 GitHub repositories. This issue allows unauthenticated users to execute harmful code, potentially impacting major organizations like Microsoft, Google, Apache, and Cloudflare. The flaw, due to weak CI/CD configurations, raises significant supply chain security concerns.
Iranian APT Group Targets Israeli Organizations with New C2 Framework
An Iranian hacking group linked to the Ministry of Intelligence and Security is targeting Israeli IT and government entities using a new command-and-control framework, Cavern C2. This development, attributed to the Cavern Manticore cluster, suggests evolving threats in cybersecurity, potentially influencing strategies in these sectors.
BeyondTrust Patches Critical Vulnerabilities in Remote Support Products
BeyondTrust has patched critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws, identified as CVE-2026-40138 and CVE-2026-40139, could allow unauthenticated attackers to bypass authentication controls and gain unauthorized access, risking elevated privilege accounts. The company urges users to apply the patches promptly.
Canadian Spy Agency Conducted Cyber Operations Against Criminal Groups
In 2022, Canada's Communications Security Establishment executed cyber operations against drug traffickers, violent extremists, and a ransomware gang. These state-authorized interventions aimed to thwart groups threatening Canada's national security and public safety. The operations utilized signals intelligence to disrupt criminal activities abroad, significantly impacting the targeted groups.
VEIL#DROP Malware Chain Uses Blogger to Deliver PureLogs Stealer
The VEIL#DROP malware delivery chain employs compromised Blogspot pages to deploy the PureLogs Stealer through multi-stage execution involving JavaScript and PowerShell. The use of trusted platforms like Google's Blogspot allows attackers to sidestep traditional defenses. Researchers have identified the sophisticated use of this infrastructure to access victims' sensitive information.
Armored Likho Targets Government and Power Sectors with Malware Attacks
The newly discovered Armored Likho group targets government and electric power sectors in Russia, Brazil, and Kazakhstan. The group uses malware, including the BusySnake Stealer, for cyber espionage and financial motives. This poses significant threats to critical infrastructure security in the affected regions.
FCA Calls for Enhanced Powers to Regulate AI in UK Financial Services
The Financial Conduct Authority (FCA) is advocating for stronger regulatory powers to tackle AI-related risks in UK financial services. A report led by FCA's Sheldon Mills highlights the potential for AI to both support consumer access and increase threats such as fraud and cybersecurity risks. The gravitation towards AI requires robust regulation to safeguard consumer interests as AI reshapes financial markets.
North Korean Hackers Launch Supply Chain Attack with Malicious Software Packages
North Korean hackers have launched the PolinRider campaign, targeting open source developers and cryptocurrency sectors through malicious software packages. The attack involves 108 unique packages and extensions, including npm libraries, Go modules, and a Chrome extension. This campaign is ongoing and poses significant risks by compromising maintainer accounts and using backdoors and information stealers.
Researchers Uncover Security Flaws in Apple AirDrop and Samsung Quick Share
Security researchers have identified six vulnerabilities in Apple's AirDrop and Samsung's Quick Share affecting billions of devices. These flaws enable nearby attackers to crash file-sharing services without user interaction. Apple has patched one of the AirDrop vulnerabilities, and investigation is ongoing for the others.
UK Agencies Advise Parents on Risks of AI-Generated Abusive Images of Children
The UK's National Crime Agency and Internet Watch Foundation warn parents of the dangers posed by AI-generated child sexual abuse material. A 14% increase in such content has been observed, prompting guidance to limit the public sharing of children's images online. Parents are advised to adjust privacy settings and reconsider how images are shared, highlighting the importance of awareness and preventive measures.
Critical Vulnerabilities Found in Cursor AI Code Editor, Prompt Urgent Update
Two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in the Cursor AI code editor, potentially allowing remote code execution by bypassing its security sandbox. These flaws, identified by Cato AI Labs, affect all versions before Cursor 3.0 and have been patched in the new release. The vulnerabilities could impact many Fortune 500 companies that use the editor, highlighting the urgency for affected users to update to version 3.0 to mitigate security risks.
FTC Urged to Maintain Privacy Audits on Musk's X amid Concerns
Privacy advocates, including the EFF, are urging the FTC to retain audits on X (formerly Twitter) to ensure data privacy compliance. X, having rebranded under Elon Musk, argues for the termination of the audits, citing redundancy with GDPR obligations. The company's history of privacy violations and corrective actions like rebranding are central to this debate, affecting millions of users.
Citrix Patches Six Critical NetScaler Vulnerabilities, Including HTTP/2 Bomb
Citrix released patches for six vulnerabilities in NetScaler ADC and Gateway, including a critical HTTP/2 Bomb exploit. These flaws, affecting versions 14.1 and 13.1, pose severe risks like denial-of-service attacks and data breaches. Organizations using these configurations should urgently update to protect against active threats.
DHS Investigates Cyber Breach on Homeland Security Information Network
The Department of Homeland Security is investigating a recent cyberattack on the Homeland Security Information Network (HSIN). The breach, suspected to occur between late May and early June, affected both HSIN servers and a SharePoint system, key for information sharing among government entities. The attack raises concerns over national security and vulnerabilities in government cybersecurity infrastructure.
Cisco Acknowledges Exploitation of Unified CM Vulnerability CVE-2026-20230
Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM). This flaw, found in systems with the WebDialer service enabled, allows attackers to execute server-side request forgery attacks and potentially gain root access. Cisco urges users to upgrade to patched versions immediately.
LayerX Reveals AI Browser Vulnerability Exploited by 'BioShocking' Attack
Security firm LayerX has discovered a vulnerability in AI-driven browsers, known as the 'BioShocking' attack, where browsers can be tricked into leaking user credentials. The attack uses game-like puzzle contexts to manipulate AI agents into bypassing security protocols, potentially exposing sensitive data. This discovery raises concerns about the security of AI-assisted browsing applications.
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized PoC Exploits
ChocoPoC, a Python-based remote access trojan, is being distributed through trojanized proof-of-concept (PoC) exploit repositories on GitHub. The malware targets cybersecurity researchers by installing malicious dependencies from PyPI, enabling attackers to execute commands and steal sensitive data. This highlights security risks associated with using unofficial PoCs in vulnerability research.
Password Spray Attack Targets Microsoft Azure CLI, Compromising 78 Accounts
An automated password spray attack on Microsoft's Azure CLI attempted over 81 million logins, affecting 78 accounts across 64 organizations. The attackers exploited a deprecated OAuth flow, bypassing security measures like Conditional Access policies and multi-factor authentication (MFA). This incident underscores vulnerabilities in prevalent security configurations within cloud environments.
ExpressVPN Enhances Password Manager with New Features
ExpressVPN has updated its password manager, ExpressKeys, to include secure sharing and passkey support. This update is part of the broader trend of meeting increasing demands for secure data management across devices.
Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA
Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.
Cloudflare joins UK's Cyber Resilience Pledge to enhance cybersecurity governance
The UK government launched the Cyber Resilience Pledge, aimed at enhancing cybersecurity governance. Cloudflare joined as a founding signatory, emphasizing collective defense principles against increasing cyber threats.