Megalodon: How Hackers Backdoored 5,500 GitHub Repos in 6 Hours — The Worst CI/CD Attack Ever
The Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories in under 6 hours, exfiltrating AWS keys, cloud credentials,…
CVEs, exploits, pentesting & threat intel
The Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories in under 6 hours, exfiltrating AWS keys, cloud credentials,…
Trend Micro Apex One zero-day CVE-2026-34926 is being exploited in the wild. CISA ordered federal agencies to patch by June…
Jacob Butler, 23, was arrested in Ottawa for operating KimWolf — an IoT botnet that enslaved 2 million devices and…
CVE-2026-46333 is a 9-year-old Linux kernel privilege escalation flaw in ptrace that lets any unprivileged user steal SSH keys, read…
TeamPCP compromised the Nx Console VS Code extension (2.2M installs) for 18 minutes — but that was enough to breach…
Socket raised $60M at a $1B valuation to stop software supply chain attacks. It blocks 1,000+ attacks weekly using behavioral…
The Verizon 2026 DBIR reveals vulnerability exploitation has overtaken stolen credentials as the #1 breach vector for the first time…
38% of all PHP websites still run EOL PHP 7, unpatched since 2022. With AI-assisted exploit development now confirmed, this…
Drupal's CVE-2026-9082 is a critical SQL injection in core — no authentication required, full database read/write access. Affects Drupal 10.4–11.3.…
Get 20+ curated tech stories, tutorials, and a free tool every week. Join 10,000+ developers.
No spam. Unsubscribe anytime.