> TODAY'S SUMMARY (105 articles)
Today's cybersecurity landscape highlights several significant threats and trends:
1. A critical vulnerability (CVE-2026-21589) in multiple Atlassian products is being actively exploited, prompting urgent patching efforts from the company. This flaw allows unauthenticated access to sensitive files.
2. The FBI and Secret Service issued warnings regarding the FortiBleed campaign, which has compromised over 86,000 Fortinet devices, locking out administrators and stealing credentials.
3. A new malware strain, PoeLLM, has created a botnet by infiltrating over 3,400 servers, cleverly disguising its infrastructure within a poem.
4. Data breaches continue to escalate, with Georgia Power and Alabama Power confirming unauthorized access to 400,000 customer accounts, and a separate breach affecting over 1 million individuals in Arizona's court system.
5. Ransomware attacks are increasingly targeting backup infrastructures, complicating recovery for victims and heightening the pressure to pay ransoms.
These developments underscore the critical need for robust security measures and prompt updates to protect against emerging threats.
|
// AI-powered summary generated at 16:00
Barracuda reveals new CypherLoc scareware has featured in nearly three million attacks
The TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension.
The post GitHub Confirms Hack Impacting 3,800 Internal Repositories appeared first on SecurityWeek.
Encryption Consulting has released CertSecure Manager v3.3, which automates zero-touch certificate renewal across all major enterprise server platforms and extends CA support to 11 providers, including Google Public CA and AWS. Certificate-related outages can cost enterprises millions in unplanned d...
Darwinium has announced updates to its Android and iOS mobile SDKs. It enables banks, payment providers, and digital businesses to tackle the proliferation of remote access scams, including those that manipulate live sessions and account farming operations that run mule networks. “Most fraud platfor...
A new study finds AI companies, defense firms, and dating apps are among 38 data collectors allegedly using manipulative design to confuse users while collecting their data.
On April 22, for roughly 90 minutes, a malicious version of Bitwarden CLI appeared on npm. Version 2026.4.0 contained a credential-stealing payload that executed an obfuscated loader and harvested AWS, Azure, GCP, GitHub, and npm tokens from any developer machine that ran npm...
One employee installed a trojanized VS Code extension. Result: ~3,800 GitHub internal repositories exfiltrated. TeamPCP claims credit, wants $50K. There is something almost ironic about GitHub, the platform that hosts the code for most of the world’s software, getting breached through a trojanized p...
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
Verizon DBIR finds 31% of data breaches began with software flaws last year
Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the company has provided step-by-step mitigation...
A Freedom of Information Act request shows the extent of the surveillance
Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future.
Read more in my article on the Hot for Security blog.
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.
The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.
"Microsoft is awar...
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. [...]
Information published.
Information published.
DirtyDecrypt (CVE-2026-31635): working PoC out for a Linux kernel LPE flaw. Missing COW guard in rxgk_decrypt_skb lets local attackers reach root. After Copy Fail, Dirty Frag, and Fragnesia, here comes DirtyDecrypt, another local privilege escalation vulnerability in the kernel, this time with a wor...
Information published.
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. [...]
In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processes,...