⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

01/06/2026 0 Comments 0 tags

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

01/06/2026 0 Comments 0 tags

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

31/05/2026 0 Comments 0 tags

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network,

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

30/05/2026 0 Comments 0 tags

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

29/05/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

29/05/2026 0 Comments 0 tags

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

29/05/2026 0 Comments 0 tags

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

29/05/2026 0 Comments 0 tags

Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

29/05/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

29/05/2026 0 Comments 0 tags

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through