Skip to content

Latest alerts

RSS feed

NPM worm in Keyv: credential theft and VS Code hooks

A credential-stealing NPM worm in Keyv spread beyond the original namespace and poisoned hundreds of npm packages. It also planted editor hooks that can trigger the payload when a workspace is trusted.

SMOKE#SCREEN Fake Updates Target ScreenConnect

Researchers uncovered SMOKE#SCREEN fake updates using Adobe/Zoom-themed lures to push ScreenConnect into victims’ systems. The campaign ends with persistent remote access via attacker-controlled relay servers.

AI-Assisted Vibe Hacking: Impact on Cyber Defense

Generative AI is changing how attackers work: less reliance on deep expertise, more iteration via natural-language help. Defenders must continuously validate security controls as exploit timelines compress.

Google removes ADK AI workflows after abuse via GitHub

Google removed three ADK AI workflows after an investigation showed that a public GitHub issue could steer a triage agent toward a privileged code-fixing agent. Potential impacts included CI execution and bot PAT theft.

Agent-to-agent attack risks in Gemini ADK Python

A researcher found an agent-to-agent attack path in Google’s Python ADK that could expose sensitive tools and enable pull request tampering. Mitigations were applied, but the scenario still required social engineering to merge malicious code.

cPanel Critical Flaw: SQL Root Privileges Fixed

cPanel has patched a cPanel critical flaw (CVE-2026-58048) that could allow an authenticated account to execute SQL with database administrative root privileges. The update also addresses additional cPanel and Exim-related issues and offers temporary workarounds.

BMC IPMI flaw: thousands of data centers at risk

A decades-old weakness in BMC management through IPMI can leak password hashes and allow offline password cracking. Thousands of internet-facing interfaces increase the urgency for patching and credential hardening.

DOUBLECUP malware service hides payloads in cached PNGs

A new Russian loader-as-a-service called DOUBLECUP stages malware through ClickFix by hiding code in images stored in the browser cache. It then decrypts and executes second-stage payloads like CountLoader and DeviceManager.