Cyber Security News

Klue OAuth Breach Exposes Third-Party SaaS Risk
Date

Klue OAuth Breach Exposes Third-Party SaaS Risk

Enterprise security teams have spent years hardening identity platforms, enforcing multifactor authentication, and strengthening endpoint security. Yet the latest compromise involving competitive intelligence platform Klue shows a different route into corporate environments: trusted third-party inte

Rokarolla: The Android Malware That Owns Your Device
Date

Rokarolla: The Android Malware That Owns Your Device

Android banking malware has steadily evolved over the past decade. What once focused primarily on stealing banking credentials has transformed into sophisticated platforms capable of remotely controlling entire devices. The emergence of Rokarolla demonstrates just how far this evolution has progress

More Than 400 Arch Linux Packages Compromised
Date

More Than 400 Arch Linux Packages Compromised

The compromise of more than 400 packages in the Arch User Repository (AUR) is one of the most significant, if not the most significant, Linux software supply chain incidents of 2026. More importantly, the campaign shows that threat actors increasingly target the trust relationships that underpin ope

Miasma Worm Code Leaked On GitHub
Date

Miasma Worm Code Leaked On GitHub

The recent surge in supply chain-focused attacks and leaked malware tooling has underscored a structural shift in modern cybercrime: attackers are no longer relying solely on isolated exploits but are increasingly industrializing malware development and distribution through developer ecosystems. Ac

SolarWinds Serv-U DoS Flaw Actively Exploited, CISA Warns
Date

SolarWinds Serv-U DoS Flaw Actively Exploited, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly exploited SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active targeting of organizations running vulnerable versions of the managed file transfer platform. The

LLMShare And The Trust Crisis In AI Platforms
Date

LLMShare And The Trust Crisis In AI Platforms

Cybercriminals have spent years refining techniques that exploit trust. They impersonate brands, abuse legitimate services, and manipulate search engines to display malicious content to unsuspecting users. The emergence of generative AI platforms has introduced another powerful trust mechanism into

Reaper Variant Of SHub Spoofs Apple Security Updates
Date

Reaper Variant Of SHub Spoofs Apple Security Updates

The operators behind the SHub macOS infostealer have introduced a more sophisticated variant called "Reaper." This shows how macOS-focused malware keeps evolving, moving beyond basic credential theft into persistent, multi-stage compromise operations. The latest campaign blends social engineering,

Shai-Hulud Campaign Marks New Era In Supply Chain Attacks
Date

Shai-Hulud Campaign Marks New Era In Supply Chain Attacks

The npm ecosystem is facing one of its most aggressive and technically sophisticated supply chain attacks to date. Over the past several months, security researchers have uncovered a sprawling malware campaign known as Shai-Hulud and its newer variant, Mini Shai-Hulud, which compromised hundreds of

Hugging Face Pushed Infostealer Via Fake OpenAI Repository
Date

Hugging Face Pushed Infostealer Via Fake OpenAI Repository

The rapid rise of open-source repositories of artificial intelligence has transformed platforms like Hugging Face into critical infrastructure for developers, researchers, and enterprises. Millions of users rely on these repositories to download models, datasets, and applications that accelerate AI