What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

15/05/2026 0 Comments 0 tags

In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

15/05/2026 0 Comments 0 tags

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data,

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

15/05/2026 0 Comments 0 tags

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

15/05/2026 0 Comments 0 tags

The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

14/05/2026 0 Comments 0 tags

Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

14/05/2026 0 Comments 0 tags

Cybersecurity researchers are sounding the alarm about what has been described as “malicious activity” in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

14/05/2026 0 Comments 0 tags

Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

14/05/2026 0 Comments 0 tags

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked

How AI Hallucinations Are Creating Real Security Risks

14/05/2026 0 Comments 0 tags

AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

14/05/2026 0 Comments 0 tags

Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure. The vulnerability in question