⤷ Title: TeamPCP Open-Sources “Shai-Hulud” AI Supply Chain Malware, Hitting NPM Fleet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:59:09 +0000
════════════════════════
⌗ Tags: #Malware #@axios_util #@chalk_tempalte #Credential Harvesting #DevSecOps 2026 #Indicator of Compromise #Malware Proliferation #npm Supply Chain Attack #Shai_Hulud Worm #TeamPCP #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:59:09 +0000
════════════════════════
⌗ Tags: #Malware #@axios_util #@chalk_tempalte #Credential Harvesting #DevSecOps 2026 #Indicator of Compromise #Malware Proliferation #npm Supply Chain Attack #Shai_Hulud Worm #TeamPCP #Typosquatting
Daily CyberSecurity
TeamPCP Open-Sources "Shai-Hulud" AI Supply Chain Malware, Hitting NPM Fleet
TeamPCP has open-sourced the Shai-Hulud supply chain worm. Multiple malicious typosquatted NPM packages are already weaponizing the AI-synthesized code.
⤷ Title: NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:51:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Mitigation #CVE_2026_42945 #Denial of Service #F5 Networks #Heap Buffer Overflow #Honeypot Telemetry #NGINX Rift #ngx_http_rewrite_module #Remote Code Execution #VulnCheck
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:51:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Mitigation #CVE_2026_42945 #Denial of Service #F5 Networks #Heap Buffer Overflow #Honeypot Telemetry #NGINX Rift #ngx_http_rewrite_module #Remote Code Execution #VulnCheck
Daily CyberSecurity
NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers
Critical 18-year-old "NGINX Rift" flaw CVE-2026-42945 is under active exploitation. Learn how to patch your proxies and block the unauthenticated heap overflow.
⤷ Title: Microsoft Announces Driver Quality Initiative to Fix Windows 11 Sleep Battery Drain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:43:06 +0000
════════════════════════
⌗ Tags: #Technology #Windows #Battery Drain Fix #C_State Sleep #Cloud_Initiated Driver Recovery #Driver Quality Initiative #Laptop Overheating #OEM Firmware #Telemetry Loophole #Windows 11 Modern Standby #Windows Hardware Compatibility #WinHEC 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:43:06 +0000
════════════════════════
⌗ Tags: #Technology #Windows #Battery Drain Fix #C_State Sleep #Cloud_Initiated Driver Recovery #Driver Quality Initiative #Laptop Overheating #OEM Firmware #Telemetry Loophole #Windows 11 Modern Standby #Windows Hardware Compatibility #WinHEC 2026
Daily CyberSecurity
Microsoft Announces Driver Quality Initiative to Fix Windows 11 Sleep Battery Drain
At WinHEC 2026, Microsoft launched the Driver Quality Initiative to penalize poorly optimized OEM hardware drivers that cause laptop overheating and sleep battery drain.
⤷ Title: By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:39:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #App_Bound Encryption #Chromium Architecture #Cleartext Credentials #Edge v148.0 Stable #Local Privilege Escalation #Memory Dump #microsoft edge #Process Memory Scraping #Threat Intelligence 2026 #Tom Jøran Sønstebyseter Rønning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:39:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #App_Bound Encryption #Chromium Architecture #Cleartext Credentials #Edge v148.0 Stable #Local Privilege Escalation #Memory Dump #microsoft edge #Process Memory Scraping #Threat Intelligence 2026 #Tom Jøran Sønstebyseter Rønning
Daily CyberSecurity
By Design No More: Microsoft Edge Vv148.0 to Block Plaintext Password Scrapes from Process Memory
Microsoft pivots on its "by design" stance, updating Edge to version 148.0 to stop caching your entire plaintext password vault in active volatile memory.
⤷ Title: Canonical Unlocks Ubuntu 26.04 LTS Upgrade Path for Ubuntu 25.10 Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:34:44 +0000
════════════════════════
⌗ Tags: #Linux #Canonical Lifecycle #Linux Desktop Security #Long Term Support Migration #Point Release Timeline #Resolute Raccoon #Software Regressions #Software Updater #System Upgrades 2026 #Ubuntu 25.10 Upgrade #Ubuntu 26.04 LTS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:34:44 +0000
════════════════════════
⌗ Tags: #Linux #Canonical Lifecycle #Linux Desktop Security #Long Term Support Migration #Point Release Timeline #Resolute Raccoon #Software Regressions #Software Updater #System Upgrades 2026 #Ubuntu 25.10 Upgrade #Ubuntu 26.04 LTS
Daily CyberSecurity
Canonical Unlocks Ubuntu 26.04 LTS Upgrade Path for Ubuntu 25.10 Users
Canonical has officially opened the GUI upgrade gate from Ubuntu 25.10 to Ubuntu 26.04 LTS. Learn why the path was delayed and what it means for 24.04 users.
⤷ Title: Mass Exploitation Alert: Hardcoded Credentials in Four-Faith Industrial Routers (CVE-2024-9643) Hijacked for Botnets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:49:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Botnet Takeover #Crowdsec #CVE_2024_9643 #F3x36 #Four_Faith #hardcoded credentials #Industrial Cellular Router #infosec #IoT security #Mass Exploitation #Nuclei Template
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:49:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Botnet Takeover #Crowdsec #CVE_2024_9643 #F3x36 #Four_Faith #hardcoded credentials #Industrial Cellular Router #infosec #IoT security #Mass Exploitation #Nuclei Template
Daily CyberSecurity
Mass Exploitation Alert: Hardcoded Credentials in Four-Faith Industrial Routers (CVE-2024-9643) Hijacked for Botnets
Urgent: CrowdSec warns CVE-2024-9643 in Four-Faith routers has hit mass exploitation phase. Attackers abuse hardcoded logins to build botnets. Patch now!
⤷ Title: Targeting 2 Million Developers: Malicious Nx Console Extension Hijacks VS Code Marketplace
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:30:49 +0000
════════════════════════
⌗ Tags: #Malware #Claude Code Hijack #Cloud Infrastructure Theft #CVE_2026_OrphanCommit #Cyber Security #infosec #MacOS backdoor #nrwl.angular_console #Nx Console #Patch Alert #supply chain attack #VS Code Marketplace
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:30:49 +0000
════════════════════════
⌗ Tags: #Malware #Claude Code Hijack #Cloud Infrastructure Theft #CVE_2026_OrphanCommit #Cyber Security #infosec #MacOS backdoor #nrwl.angular_console #Nx Console #Patch Alert #supply chain attack #VS Code Marketplace
Daily CyberSecurity
Targeting 2 Million Developers: Malicious Nx Console Extension Hijacks VS Code Marketplace
Urgent: Malicious Nx Console v18.95.0 briefly hit the VS Code Marketplace, targeting 2M+ installs with a macOS backdoor and token stealer. Audit now!
⤷ Title: Massive PostgreSQL Update: 11 Vulnerabilities Patched as Version 14 Hits End-of-Life Warning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2026_6477 #CVE_2026_6637 #database security #DevOps #infosec #Patch Alert #Postgres Update #PostgreSQL #sql injection #SysAdmin
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 02:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2026_6477 #CVE_2026_6637 #database security #DevOps #infosec #Patch Alert #Postgres Update #PostgreSQL #sql injection #SysAdmin
Daily CyberSecurity
Massive PostgreSQL Update: 11 Vulnerabilities Patched as Version 14 Hits End-of-Life Warning
PostgreSQL releases updates for versions 14-18 fixing 11 vulnerabilities (CVSS 8.8). Plus, critical End-of-Life deadline issued for Postgres 14.
⤷ Title: PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:51:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2005 #database security #Heap Buffer Overflow #infosec #Patch Alert #pgcrypto #PoC Exploit #PostgreSQL #Public Disclosure #rce #Superuser Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:51:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2005 #database security #Heap Buffer Overflow #infosec #Patch Alert #pgcrypto #PoC Exploit #PostgreSQL #Public Disclosure #rce #Superuser Escalation
Daily CyberSecurity
PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE
Technical details and GitHub PoC exploits disclosed for PostgreSQL pgcrypto CVE-2026-2005. Low-privilege users can seize root superuser RCE. Patch now!
⤷ Title: Breaking the AI Sandbox: Critical Flowise Flaw (CVE-2026-46442) Grants Host-Level RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agent Security #code_injection #CVE_2026_46442 #Cyber Security #Flowise #infosec #LLM Orchestration #NodeVM #Patch Alert #Remote Code Execution #Sandbox Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agent Security #code_injection #CVE_2026_46442 #Cyber Security #Flowise #infosec #LLM Orchestration #NodeVM #Patch Alert #Remote Code Execution #Sandbox Escape
Daily CyberSecurity
Breaking the AI Sandbox: Critical Flowise Flaw (CVE-2026-46442) Grants Host-Level RCE
CVE-2026-46442 in Flowise allows authenticated users to escape the NodeVM sandbox and execute system commands. Secure your AI infrastructure now!
⤷ Title: Critical Portainer Flaws Grant Restricted Users Root Access to the Host
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:10:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_44848 #CVE_2026_44849 #Cyber Security #DevSecOps #Docker Swarm #infosec #Patch Alert #Portainer #privilege escalation #RBAC Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:10:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_44848 #CVE_2026_44849 #Cyber Security #DevSecOps #Docker Swarm #infosec #Patch Alert #Portainer #privilege escalation #RBAC Bypass
Daily CyberSecurity
Critical Portainer Flaws Grant Restricted Users Root Access to the Host
Portainer fixes two critical 9.4 CVSS flaws (CVE-2026-44848/49) allowing instant container escape to host root. Patch your environments now!
⤷ Title: Critical 9.8 CVSS: Severe SQL Injection Flaw Exposed in Marten .NET Document Store Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:04:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Security #ACID Document Database #CVE_2026_45288 #Cyber Security #Full_Text Search #infosec #Marten .NET #Patch Alert #PostgreSQL #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 01:04:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Security #ACID Document Database #CVE_2026_45288 #Cyber Security #Full_Text Search #infosec #Marten .NET #Patch Alert #PostgreSQL #sql injection
Daily CyberSecurity
Critical 9.8 CVSS: Severe SQL Injection Flaw Exposed in Marten .NET Document Store Engine
Marten .NET library suffers a critical 9.8 CVSS SQL injection flaw (CVE-2026-45288). Learn how to block the exploit and patch your databases now!
⤷ Title: Ethereum Deep Dive Part 2: EVM & Opcodes
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:31:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #smart_contracts #web3 #ethereum
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:31:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #smart_contracts #web3 #ethereum
Medium
Ethereum Deep Dive Part 2: EVM & Opcodes
Series: Web3 Security Zero se Advance | Article #4 By HackerMD | 24 min read
⤷ Title: TryHackMe : Server-side Template Injection Task 8
════════════════════════
𐀪 Author: Rindaman666
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:15:33 GMT
════════════════════════
⌗ Tags: #learning #data_science #ethical_hacking #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Rindaman666
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:15:33 GMT
════════════════════════
⌗ Tags: #learning #data_science #ethical_hacking #tryhackme #cybersecurity
Medium
TryHackMe : Server-side Template Injection Task 8
Exploit various templating engines that lead to SSTI vulnerability.
⤷ Title: Network Revision — part 5
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:52:06 GMT
════════════════════════
⌗ Tags: #web_development #cyber_security_awareness #cybersecurity #ethical_hacking #infosec
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:52:06 GMT
════════════════════════
⌗ Tags: #web_development #cyber_security_awareness #cybersecurity #ethical_hacking #infosec
Medium
Network Revision — part 5
How does websites work ?
⤷ Title: Paywall bypass exposing the premium articles for free
════════════════════════
𐀪 Author: LogicHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:50:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #hacking #ctf #cybersecurity
════════════════════════
𐀪 Author: LogicHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:50:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #hacking #ctf #cybersecurity
Medium
Paywall bypass exposing the premium articles for free
Hi everyone,
⤷ Title: Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 10:58:06 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 10:58:06 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 10:24:17 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 10:24:17 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Boot Partition Bottleneck: Microsoft Confirms Windows 11 Update KB5089549 Fails with Error 0x800f0922
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:07 +0000
════════════════════════
⌗ Tags: #Windows #EFI System Partition #Enterprise Group Policy #Error 0x800f0922 #ESP Low Space #KB5089549 #Known Issue Rollback #Patch Tuesday 2026 #ServicingBootFiles #SpaceCheck #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:07 +0000
════════════════════════
⌗ Tags: #Windows #EFI System Partition #Enterprise Group Policy #Error 0x800f0922 #ESP Low Space #KB5089549 #Known Issue Rollback #Patch Tuesday 2026 #ServicingBootFiles #SpaceCheck #Windows 11
Daily CyberSecurity
Boot Partition Bottleneck: Microsoft Confirms Windows 11 Update KB5089549 Fails with Error 0x800f0922
Microsoft confirms Windows 11 update KB5089549 fails and rolls back at 35% with error 0x800f0922 on systems with low EFI partition storage. Learn the fix.
⤷ Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Daily CyberSecurity
Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
The Mini Shai-Hulud npm worm has hijacked the atool account, poisoning AntV & timeago.js to scrape GitHub runner memory. Execute a full reset now!
⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!