Microsoft released patches for 137 CVEs across Windows, Azure, Office, Edge, and more, with 30 rated critical. Standouts include CVE-2026-41089 (Windows Netlogon, unauthenticated RCE on domain controllers) and CVE-2026-41096 (Windows DNS Client RCE), both high-impact targets for rapid exploitation even as no active attacks are currently reported.
Source: SecurityWeek
Fresh supply-chain attack poisons npm and PyPI packages in “Mini Shai‑Hulud” wave
Over 400 malicious versions of 170 packages were pushed in a rapid campaign hitting TanStack, Mistral AI, UiPath and others, with payloads stealing CI/CD secrets and developer credentials. Notably, the attackers shipped valid provenance for doctored artifacts, underscoring that signed builds don’t guarantee safe pipelines and that dependency and workflow hardening are essential.
Source: SecurityWeek
TeamPCP open-sources Shai‑Hulud tooling, lowering the barrier for copycat supply-chain attacks
Researchers report the Shai‑Hulud worm code has been released publicly, including techniques to forge trust and extract OIDC tokens from CI/CD. This elevates risk beyond a single actor, making mis-scoped identity, cache poisoning, and insufficient workflow isolation urgent audit items for any org publishing to npm or PyPI.
Source: Vectra Networks
Google flags first known AI‑assisted zero‑day exploit seen in the wild
Attackers used AI to help craft an exploit script for a two‑factor authentication bypass in an open-source project, according to Google. The case highlights how AI can compress exploit development timelines, shrinking defenders’ patch windows and raising the premium on rapid detection and coordinated disclosure.
Source: SC Media
“Copy.Fail” dubbed worst Linux kernel bug in years enables stealth local privilege escalation
Theori’s Copy.Fail (CVE‑2026‑31431) abuses AF_ALG sockets and splice() to overwrite file page cache contents four bytes at a time, letting attackers escalate privileges without touching the file on disk. The exploit works reliably across major distros and evades checksum-based integrity tools, making rapid kernel patching and AF_ALG hardening priorities.
Source: Schneier on Security
Fortinet and Ivanti ship critical fixes that can lead to code execution and data exposure
Fortinet addressed critical issues in FortiSandbox and FortiAuthenticator (e.g., CVE‑2026‑44277), while Ivanti patched high‑severity bugs across its portfolio. Given these products’ placement at security boundaries, organizations should prioritize updates, review external exposure, and hunt for suspicious management activity.
Source: SecurityWeek
Android adds ‘Intrusion Logging’ to expose sophisticated spyware operations
Google, working with Amnesty International, introduced an opt‑in Advanced Protection Mode feature that preserves privacy‑aware forensic logs to aid detection and investigation of high‑end spyware. It’s the first vendor‑level capability designed to make stealth mobile intrusions more visible to defenders and investigators.
Source: CyberScoop
You May Also Be Interested In... - Apple Patches Dozens of Vulnerabilities in macOS, iOS - Foxconn confirms cyberattack impacting North American factories - Global cyber threats spike in April 2026, ransomware expands