home / cybersecurity
🛡️

Cybersecurity

CVEs, exploits, pentesting & threat intel

73 posts // cybersecurity updated daily
Megalodon GitHub supply chain attack 5500 repos backdoored 2026

Megalodon: How Hackers Backdoored 5,500 GitHub Repos in 6 Hours — The Worst CI/CD Attack Ever

The Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories in under 6 hours, exfiltrating AWS keys, cloud credentials,…

Trend Micro Apex One zero-day CVE-2026-34926 CISA patch alert 2026

Hackers Are Exploiting a Trend Micro Apex One Zero-Day Right Now — CISA Says Patch by June 4 or Else

Trend Micro Apex One zero-day CVE-2026-34926 is being exploited in the wild. CISA ordered federal agencies to patch by June…

KimWolf botnet arrest DDoS 30 Tbps 2 million devices 2026

The 23-Year-Old Behind the Largest DDoS Botnet in History Just Got Arrested — 2 Million Devices, 30 Tbps Attacks

Jacob Butler, 23, was arrested in Ottawa for operating KimWolf — an IoT botnet that enslaved 2 million devices and…

CVE-2026-46333 Linux kernel 9-year privilege escalation vulnerability

A 9-Year-Old Linux Kernel Bug Just Let Attackers Steal SSH Keys and Get Root on Every Major Distro

CVE-2026-46333 is a 9-year-old Linux kernel privilege escalation flaw in ptrace that lets any unprivileged user steal SSH keys, read…

GitHub breached via Nx Console VS Code supply chain attack 2026

A Poisoned VS Code Extension Just Gave Hackers Access to 3,800 GitHub Repos — In 18 Minutes

TeamPCP compromised the Nx Console VS Code extension (2.2M installs) for 18 minutes — but that was enough to breach…

Socket security startup 60M Series C supply chain protection 2026

This $1B Security Startup Is Silently Blocking Nation-State Hackers From Your Code — Socket Raises $60M in 2026

Socket raised $60M at a $1B valuation to stop software supply chain attacks. It blocks 1,000+ attacks weekly using behavioral…

Verizon DBIR 2026 vulnerability exploitation overtakes credentials

Verizon DBIR 2026: For the First Time Ever, Hackers Prefer Exploiting Bugs Over Stolen Passwords

The Verizon 2026 DBIR reveals vulnerability exploitation has overtaken stolen credentials as the #1 breach vector for the first time…

PHP 7 end-of-life security vulnerability AI exploits 2026

The PHP 7 Time Bomb: 38% of the Web Runs End-of-Life PHP — And AI Is About to Set It Off

38% of all PHP websites still run EOL PHP 7, unpatched since 2022. With AI-assisted exploit development now confirmed, this…

Drupal CVE-2026-9082 critical SQL injection unauthenticated vulnerability

Drupal CVE-2026-9082: Unauthenticated SQL Injection in Core — Government and University Sites at Immediate Risk

Drupal's CVE-2026-9082 is a critical SQL injection in core — no authentication required, full database read/write access. Affects Drupal 10.4–11.3.…