The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to
Category Added in a WPeMatico Campaign
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times.
Phishing crews are getting smarter too – less obvious scam junk, more targeted stuff that actually
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost’s Content API that could allow an unauthenticated attacker to read arbitrary data from the
The Alert Firehose Finally Meets Its Match
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader.
“DPAPILoader decrypts and
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves from a cluster of
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
“Although the affected packages were all Composer packages, the malicious code was not added to composer.json,” Socket said. “Instead, it was inserted into package.json, targeting projects that ship JavaScript
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Project Glasswing is an effort led by the artificial intelligence (AI) company, as part of which a small set of about 50 partners
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
The affected packages include –
laravel-lang/lang
laravel-lang/http-statuses
laravel-lang/attributes
laravel-lang/actions
“The timing and pattern of the newly published tags
