The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege
Category Added in a WPeMatico Campaign
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
The way in was a backdoor on their REDCap research servers that stole login credentials. The exfiltration was the unusual part: the attackers rewired the victims’ own Google Workspace rules to copy any message
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface.
A server takeover exposes every provider key it holds, the secrets that
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else’s entry point.
Scroll through the full Monday Cybersecurity
The Onboarding Password Mistake That Creates Unnecessary Risk
That usually means sharing a temporary “first-day” password so employees can access systems for the first time. The issue is that these passwords don’t always stay temporary. They may be sent over email or SMS, reused across accounts,
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
“These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,” Group-IB
