22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters

21/04/2026 0 Comments 0 tags

Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

21/04/2026 0 Comments 0 tags

A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, teamed

5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time

21/04/2026 0 Comments 0 tags

Security teams often present MTTR as an internal KPI. Leadership sees it differently: every hour a threat dwells inside the environment is an hour of potential data exfiltration, service disruption,

Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution

21/04/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a vulnerability in Google’s agentic integrated development environment (IDE), Antigravity, that could be exploited to achieve code execution. The flaw, since patched, combines Antigravity’s permitted file-creation

NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs

21/04/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a new iteration of an Android malware family called NGate that has been found to abuse a legitimate application called HandyPay instead of NFCGate. “The threat actors took the

No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks

21/04/2026 0 Comments 0 tags

The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn’t

CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

21/04/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing

SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

20/04/2026 0 Comments 0 tags

A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS

⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

20/04/2026 0 Comments 0 tags

Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

20/04/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a critical “by design” weakness in the Model Context Protocol’s (MCP) architecture that could pave the way for remote code execution and have a cascading effect