KnowledgeDeliver CVE-2026-5426: Zero-Day RCE via Shared ASP.NET Machine Key
May 26, 2026 Threat actors exploited a critical zero-day vulnerability in KnowledgeDeliver, a Japanese learning management system (LMS), to deploy the Godzilla web shell and infect targeted users with Cobalt Strike. The flaw, now tracked as…
AI Chatbot Cryptojacking Campaign Targets GPU Users via Malicious Software Sites
May 27, 2026 Microsoft has uncovered an active cryptojacking campaign that leverages artificial intelligence chatbot interactions to deliver malicious software to users searching for trusted system utilities. The campaign impersonates legitimate…
7-Eleven Data Breach Exposes 185,000 People: ShinyHunters Extortion Gang Strikes
May 26, 2026 Convenience store giant 7-Eleven has confirmed a data breach that exposed the personal information of 185,300 people after the ShinyHunters extortion gang compromised its systems in early April 2026. Consequently, the cybercriminals leaked a…
Kali365 PhaaS Hijacks Microsoft 365 Accounts via Device Code Phishing
May 25, 2026 The FBI is warning organizations about Kali365, a phishing-as-a-service (PhaaS) platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication. The service bypasses multi-factor authentication (MFA) and has already…
Cisco Secure Workload CVE-2026-20223: Max Severity Site Admin Bypass
May 21, 2026 Cisco has patched a maximum severity vulnerability in Cisco Secure Workload that lets unauthenticated attackers gain full Site Admin privileges. The flaw, tracked as CVE-2026-20223, impacts the product’s internal REST APIs and carries…
Ghost CMS SQL Injection CVE-2026-26980: ClickFix Campaign Hits 700+ Domains
May 24, 2026 A large-scale campaign is actively exploiting a critical SQL injection vulnerability in Ghost CMS to inject malicious JavaScript that drives ClickFix attack flows. The campaign has already compromised more than 700 domains, including…
DoJ Disrupts Kimwolf Botnet: 3 Million Devices Behind DDoS Attacks
May 24, 2026 The U.S. Department of Justice announced on March 20, 2026, a major international law enforcement operation that disrupted command-and-control infrastructure powering four massive IoT botnets. This operation successfully dismantled the…
Ubiquiti Patches Three Maximum Severity UniFi OS Vulnerabilities
May 24, 2026 Ubiquiti has released urgent security updates for three maximum severity UniFi OS vulnerabilities that allow remote attackers to compromise systems without authentication. These flaws affect the core operating system powering UniFi Consoles…
Laravel Lang Supply Chain Attack Spreads Credential-Stealing Malware to Developers
May 23, 2026 A sophisticated supply chain attack has compromised the Laravel Lang localization packages after attackers rewrote GitHub version tags to distribute credential-stealing malware through Composer. Security researchers from StepSecurity, Aikido…
US Gas Station Tank Gauges Breached by Unknown Threat Actors
May 18, 2026 Unknown threat actors have breached automatic tank gauge (ATG) systems at US gas stations in multiple states. The attackers exploited these systems to manipulate display readings on fuel tanks. However, they did not alter the actual fuel…