TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
“Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to
OpenAI Hit by TanStack Supply Chain Attack
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
The post OpenAI Hit by TanStack Supply Chain Attack appeared first on SecurityWeek.
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.
Microsoft warns of Exchange zero-day flaw exploited in attacks
Chrome 148 Update Patches Critical Vulnerabilities
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.
The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.
“
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It’s
