Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Kimwolf DDoS Botnet: Canadian Operator Arrested and Charged
The US Department of Justice announced the arrest of 23-year-old Canadian citizen Jacob Butler (alias Dort) from Ottawa on charges ...
How a Malicious VS Code Extension Exposed 3,800 Internal GitHub Repos
GitHub has confirmed a supply chain attack that resulted in the compromise of approximately 3,800 of the company’s internal repositories. ...
Langflow RCE and Apex One directory traversal added to CISA KEV
On May 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to the Known Exploited Vulnerabilities ...
Active exploitation of Microsoft Defender CVE-2026-41091 and CVE-2026-45498
Microsoft has confirmed active exploitation of two vulnerabilities in Microsoft Defender: CVE-2026-41091 (privilege escalation to SYSTEM, CVSS 7.8) and CVE-2026-45498 ...
How Microsoft’s RAMPART and Clarity Bring Security into AI Agent Development
Microsoft has introduced two open-source tools — RAMPART and Clarity — designed to test the security of AI agents directly ...
How Hidden Identities and AI Agents Undermine Enterprise IAM
The company Orchid Security has published the report Identity Gap: Snapshot 2026, according to which 57% of corporate identity infrastructure ...
Why Mozilla Warns UK VPN Restrictions Threaten Online Privacy
Mozilla has submitted an official appeal to the Ministry of Science, Innovation and Technology of the United Kingdom (DSIT), in ...
How the Nx Console VS Code Extension Was Used to Steal Dev Credentials
The popular Nx Console extension for Visual Studio Code (version 18.95.0) was compromised and used to deliver multi-stage malware that ...
TeamPCP’s Mini Shai-Hulud Campaign and the Compromise of GitHub and durabletask
GitHub is investigating unauthorized access to its internal repositories, while at the same time the TeamPCP group is continuing a ...