“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm [email protected] (The Hacker News)
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potentialRead More
-

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More [email protected] (The Hacker News)
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already…
-

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan [email protected] (The Hacker News)
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachmentsRead More
-

The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools [email protected] (The Hacker News)
Three years ago, the practical question for an MSP building a cybersecurity practice was which “vCISO platform” to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more…
-

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from…
-

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts [email protected] (The Hacker News)
Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location…
-

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices [email protected] (The Hacker News)
Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in…
-

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation [email protected] (The Hacker News)
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. “Authentication bypass vulnerabilities…
-

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. “The chatgpt.com response renderer trusts Markdown links and MarkdownRead More
-
EO 14390 raises stakes for enterprise cybersecurity
Reframing cybercrime as a national security issue, EO 14390 could lead to stronger links between government and the private sector. Find out what it means for enterprise security.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
