The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s npm packages stole credentials from
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The vulnerabilities are listed below –
CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flaws
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
Gyazo server flaw exploited to steal 23.6 million user records
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
