🦜 CyberNetSec - Latest Cybersecurity Articles
@cyber.netsecops.io@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Latest cybersecurity threat intelligence articles from the past 3 days
Your feed and you don't want it here? Just
e-mail the birb.
CISA Contractor Leaks AWS GovCloud Keys and Internal System Credentials on Public GitHub Repo
https://cyber.netsecops.io/articles/cisa-contractor-leaks-govcloud-keys-on-public-github-sparking-congressional-inquiry/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is under congressional investigation after a contractor exposed highly sensitive credentials on a public GitHub repository. The repository, named 'Private-CISA,' contained plaintext…
TeamPCP Threat Actor Breaches TanStack in 'Mini Shai-Hulud' Supply Chain Campaign
https://cyber.netsecops.io/articles/teampcp-mini-shai-hulud-campaign-breaches-tanstack-in-widespread-supply-chain-attack/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
The financially motivated threat group 'TeamPCP' has been identified as the actor behind the 'Mini Shai-Hulud' supply chain campaign, which recently compromised the popular TanStack open-source library. The attack, which also targeted the npm and PyPI…
‘Megalodon’ Campaign Hits 5,500+ GitHub Repos in Automated CI/CD Supply Chain Attack
https://cyber.netsecops.io/articles/megalodon-attack-poisons-over-5500-github-repos-with-malicious-ci-cd-workflows/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
A massive, automated supply chain attack dubbed 'Megalodon' has compromised over 5,500 public GitHub repositories in just six hours. The attackers pushed thousands of malicious commits that altered CI/CD workflow files, backdooring the build processes of…
Akamai Report: Financial Sector Under Siege from AI-Powered Botnets and Escalating DDoS Attacks
https://cyber.netsecops.io/articles/akamai-report-ai-powered-botnets-and-ddos-attacks-escalating-against-financial-sector/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
According to a new 'State of the Internet' report from Akamai, the financial services sector is facing a growing threat from increasingly sophisticated cyberattacks. The report highlights the use of AI-empowered botnets that operate with greater speed and…
'Trapdoor' Android Ad Fraud Campaign Used 455 Malicious Apps to Hijack Millions of Devices
https://cyber.netsecops.io/articles/trapdoor-android-ad-fraud-operation-hijacks-millions-of-devices/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
A sophisticated and large-scale Android ad fraud operation named 'Trapdoor' has been uncovered by security researchers. The campaign involved a network of 455 malicious apps, downloaded over 24 million times from the Google Play Store, that worked together…
Trump Mobile API Flaw Exposes Personal Data of 27,000 Smartphone Pre-Order Customers
https://cyber.netsecops.io/articles/trump-mobile-investigates-data-leak-of-27000-pre-orders-after-unprotected-api-discovery/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 24, 2026 00:00
Trump Mobile is investigating a significant data exposure incident affecting approximately 27,000 customers who pre-ordered the company's T1 smartphone. A security researcher discovered an unprotected API endpoint that allowed public access to customer…
New 'Underminr' Flaw in CDNs Puts 88 Million Domains at Risk of Evasive Attacks
https://cyber.netsecops.io/articles/underminr-cdn-vulnerability-exposes-88-million-domains-to-domain-fronting-attacks/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 23, 2026 00:00
A newly disclosed vulnerability named 'Underminr' affects shared Content Delivery Network (CDN) infrastructure, enabling a sophisticated form of domain fronting. The flaw allows attackers to hide malicious command-and-control (C2) traffic behind an…
Laravel-Lang Supply Chain Attack Injects Credential Stealer into 233 Package Versions
https://cyber.netsecops.io/articles/laravel-lang-supply-chain-attack-compromises-over-200-package-versions/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 23, 2026 00:00
A major supply chain attack has targeted the popular Laravel-Lang project, used for language localization in the Laravel PHP framework. Attackers compromised 233 version tags across three key repositories, injecting a multi-stage credential-stealing…
Critical Unauthenticated SQLi Flaw in Drupal Core Hits PostgreSQL Sites
https://cyber.netsecops.io/articles/critical-sql-injection-vulnerability-cve-2026-9082-in-drupal-core-for-postgresql/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 23, 2026 00:00
The Drupal project has released security updates to patch a critical SQL injection vulnerability, tracked as CVE-2026-9082. The flaw affects Drupal Core sites that use a PostgreSQL database backend. It can be exploited by an unauthenticated, anonymous…
Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware
https://cyber.netsecops.io/articles/coordinated-packagist-attack-infects-php-projects-with-linux-malware/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 23, 2026 00:00
A coordinated supply chain attack has compromised at least eight packages on Packagist, the main PHP package repository. The attackers modified the packages to download and execute a Linux binary hosted on GitHub. In a clever evasion tactic, the malicious…
Gartner Names LinkShadow a 'Visionary' in 2026 Magic Quadrant for Network Detection and Response
https://cyber.netsecops.io/articles/gartner-recognizes-linkshadow-as-visionary-in-2026-ndr-magic-quadrant/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 23, 2026 00:00
The technology research firm Gartner has positioned LinkShadow in the Visionaries Quadrant of its 2026 Magic Quadrant for Network Detection and Response (NDR). This recognition highlights LinkShadow's completeness of vision and ability to execute in the…
CISA KEV Catalog Updated: Actively Exploited Langflow and Trend Micro Flaws Demand Urgent Patching
https://cyber.netsecops.io/articles/cisa-adds-langflow-and-trend-micro-bugs-to-kev-catalog/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are under active exploitation. The flaws are CVE-2025-34291, an Origin Validation Error…
New 'Aur0ra' Ransomware Emerges with Stealthy Dual-Extortion Tactics
https://cyber.netsecops.io/articles/new-aur0ra-ransomware-employs-dual-extortion-without-renaming-files/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
A new ransomware strain named Aur0ra has been identified, employing a dual-extortion model that is becoming standard for modern ransomware. The malware encrypts files, making them inaccessible, and claims to have exfiltrated sensitive data before…
Vietnam Government Systems Breached, SOCs Fail to Detect Intrusions
https://cyber.netsecops.io/articles/vietnamese-ministry-systems-breached-in-major-cyberattack/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Vietnamese cybersecurity authorities are investigating major data breaches at two unnamed ministry-level agencies, where hackers have allegedly stolen millions of user records. According to the Vietnam National Cyber Emergency Response Team (VNCERT), the…
Iranian APT 'Screening Serpens' Intensifies Espionage with New RATs Targeting US, Israel, and UAE
https://cyber.netsecops.io/articles/iranian-apt-screening-serpens-escalates-espionage-with-new-rats/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
The Iran-nexus advanced persistent threat (APT) group known as Screening Serpens (also UNC1549, Smoke Sandstorm) has escalated its cyber-espionage activities, according to researchers at Unit 42. The campaigns, which ran from mid-February to April 2026,…
Industrial Giants Under Siege: Foxconn and Škoda Auto Suffer Major Cyberattacks
https://cyber.netsecops.io/articles/foxconn-and-skoda-auto-hit-by-separate-cyberattacks-in-may-2026/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Two major multinational corporations, electronics manufacturer Foxconn and automaker Škoda Auto, have been targeted in separate, significant cyberattacks in May 2026. Foxconn's North American facility was struck by the Nitrogen ransomware group, resulting…
AI Amplifies Supply Chain Threats, Creating New and Complex Cyber Risks
https://cyber.netsecops.io/articles/ai-exacerbates-cybersecurity-risks-in-global-supply-chains/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
The rapid integration of Artificial Intelligence (AI) into global supply chains is creating a new and complex risk landscape. While AI offers benefits in automation and analytics, it also introduces a new attack surface for threat actors. Malicious actors…
Massive HIPAA Breach Wave Hits U.S. Healthcare, Exposing Thousands of Patient Records
https://cyber.netsecops.io/articles/hipaa-data-breaches-expose-patient-data-across-multiple-us-healthcare-entities/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Multiple U.S. healthcare organizations, including the World Trade Center Health Program and LHC Group, have disclosed significant data breaches throughout May 2026. These incidents, some orchestrated by ransomware groups like TridentLocker, have resulted…
Iranian APT Screening Serpens Unleashes New RATs in Espionage Campaign Against US, Israel, and UAE
https://cyber.netsecops.io/articles/tracking-iranian-apt-screening-serpens-2026-espionage-campaigns/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Unit 42 has identified a series of cyberespionage campaigns conducted by the Iran-nexus Advanced Persistent Threat (APT) group Screening Serpens (also known as UNC1549) between February and April 2026. The attacks, which align with regional conflicts,…
Germany Becomes Epicenter of European Cyber Conflict with 124% Surge in Attacks
https://cyber.netsecops.io/articles/germany-faces-escalating-cyber-campaigns-from-hacktivists-and-ransomware/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Cyberattacks in the DACH region (Germany, Austria, Switzerland) surged by 124% in 2025, with Germany bearing the brunt, accounting for 82% of all incidents. According to research from Check Point, this dramatic increase is fueled by a dual threat:…
Nation-State Actors Weaponize Open-Source ROADtools for Azure Cloud Attacks, Bypassing MFA and Persisting in Networks
https://cyber.netsecops.io/articles/roadtools-nation-state-tactics-in-the-cloud/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 22, 2026 00:00
Nation-state threat actors, including Midnight Blizzard and Curious Serpens, are increasingly misusing ROADtools, a legitimate open-source framework for Azure and Entra ID security research, to conduct sophisticated cloud attacks. According to Unit 42,…
Warning: Microsoft Defender Flaws Actively Exploited to Gain SYSTEM Privileges
https://cyber.netsecops.io/articles/microsoft-defender-vulnerabilities-actively-exploited-for-privilege-escalation/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 21, 2026 00:00
Microsoft has confirmed that two vulnerabilities in its Microsoft Defender antivirus solution, CVE-2026-41091 and CVE-2026-45498, are being actively exploited in the wild. The more severe flaw, CVE-2026-41091, is a local privilege escalation (LPE)…
CrowdStrike: North Korea Stole Billions in Crypto, Financial Sector Attacks Up 43%
https://cyber.netsecops.io/articles/crowdstrike-report-dprk-stole-billions-financial-intrusions-spiked/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 21, 2026 00:00
CrowdStrike's 2026 Financial Services Threat Landscape Report, released May 20, 2026, details a massive escalation in cyberattacks against the financial sector, driven by North Korean state actors and organized eCrime groups. DPRK-nexus adversaries, such…
CISA Adds Seven New Vulnerabilities to 'Must-Patch' KEV Catalog
https://cyber.netsecops.io/articles/cisa-adds-seven-known-exploited-vulnerabilities-to-kev-catalog-may-20-2026/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 21, 2026 00:00
On May 20, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This action, under Binding Operational Directive (BOD) 22-01, mandates that Federal…
Supply Chain in Crisis: Exploits Now Arrive Before Companies Know They're Vulnerable
https://cyber.netsecops.io/articles/supply-chain-security-crisis-velocity-without-visibility/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 21, 2026 00:00
A May 2026 report from Black Kite warns of a deepening supply chain security crisis, characterized by 'Velocity Without Visibility.' With over 48,000 CVEs published in 2025, the speed of exploitation has now surpassed the speed of discovery for many…
CISA Opens KEV Catalog to Public Submissions to Speed Up Threat Response
https://cyber.netsecops.io/articles/cisa-invites-security-community-to-nominate-known-exploited-vulnerabilities/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 21, 2026 00:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new public-facing submission process for its Known Exploited Vulnerabilities (KEV) catalog. Announced on May 21, 2026, the initiative allows security researchers, vendors, and…
BWH Hotels Breach: Attackers Had Access for Six Months, Exposing Guest Data
https://cyber.netsecops.io/articles/bwh-hotels-confirms-data-breach-exposing-guest-reservation-data/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
BWH Hotels, the parent company of major brands like Best Western, WorldHotels, and SureStay, has confirmed a significant data breach involving sensitive guest reservation information. The breach was discovered on April 22, but investigations revealed that…
Six Windows Zero-Day Exploits Leaked by Threat Actor 'Nightmare-Eclipse'
https://cyber.netsecops.io/articles/threat-actor-nightmare-eclipse-leaks-six-windows-zero-day-exploits/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
A threat actor operating under the alias 'Nightmare-Eclipse' has released a series of six zero-day exploits targeting Microsoft Windows. The campaign, which appears to be a personal vendetta against Microsoft rather than financially motivated, includes…
Chinese APT 'Webworm' Uses Discord and MS Graph API for C2 in New Backdoor Attacks
https://cyber.netsecops.io/articles/china-aligned-webworm-apt-deploys-new-backdoors-using-discord-and-ms-graph/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
The China-aligned threat actor known as 'Webworm' has been observed deploying two new, sophisticated backdoors named 'EchoCreep' and 'GraphWorm'. These tools represent an evolution in the group's tactics, using legitimate and widely-used services for…
Global Consulting Services Breach Exposes PII of 1,320 Individuals
https://cyber.netsecops.io/articles/global-consulting-services-discloses-data-breach-exposing-pii/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
Global Consulting Services & Software Development, a California-based IT firm, has disclosed a data breach that exposed the personally identifiable information (PII) of 1,320 individuals. The breach occurred in early January 2026 when an unauthorized third…
Ransomware Attack on West Pharmaceutical Services Disrupts Global Operations
https://cyber.netsecops.io/articles/west-pharmaceutical-services-hit-by-ransomware-attack/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
West Pharmaceutical Services, a leading global manufacturer of pharmaceutical packaging and drug delivery systems, has suffered a ransomware attack that disrupted its global business operations. The company detected unusual network activity on May 4 and…
NYC Health + Hospitals Breach May Affect 1.8 Million Patients and Employees
https://cyber.netsecops.io/articles/nyc-health-hospitals-reports-massive-data-breach-affecting-1-8-million/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
NYC Health + Hospitals Corporation, the largest public health system in the United States, has reported a massive data breach that may have compromised the personal and protected health information (PHI) of approximately 1.8 million people. The breach,…
TamperedChef Malware: Trojanized Apps Masquerade as Productivity Tools to Deploy Stealthy Payloads
https://cyber.netsecops.io/articles/tracking-tamperedchef-clusters-via-certificate-and-code-reuse/?utm_source=rss&utm_medium=feed&utm_campaign=all
Published: May 20, 2026 00:00
Unit 42 has identified and analyzed several clusters of malware activity collectively known as TamperedChef. This threat involves trojanized productivity applications, such as PDF editors and file converters, distributed through malicious advertising…