Attackers compromised 32 @redhat-cloud-services npm packages, publishing 96 malicious versions laced with a credential‑stealing worm similar to Mini Shai‑Hulud. The campaign targets developer workstations and CI/CD environments, raising the risk of token leakage and downstream propagation across build pipelines. Teams should audit recent installs, rotate exposed secrets, and pin/verify package integrity.
Source: SecurityWeek
Windows Netlogon RCE now actively exploited (CVE-2026-41089)
A critical stack-based buffer overflow in Windows Netlogon is under active exploitation, putting domain controllers at immediate risk. Attackers can achieve unauthenticated remote code execution by sending crafted network requests; urgent patching and tightened DC network controls are advised.
Source: SecurityWeek
Palo Alto GlobalProtect VPN auth bypass under attack (CVE-2026-0257)
Palo Alto Networks’ PAN‑OS GlobalProtect VPN is facing “limited exploit attempts” abusing an authentication bypass via forged cookies. While patches were released May 13, telemetry shows successful login bypasses at multiple customers—organizations should urgently apply fixes, revoke sessions, and review VPN access logs.
Source: Help Net Security
Dutch police dismantle 17-million-device botnet powering proxy cybercrime
Authorities in the Netherlands seized command‑and‑control servers tied to a sprawling botnet of 17 million infected devices. The infrastructure allegedly fueled a residential proxy network used to facilitate cybercrime, highlighting the continued monetization of compromised consumer IoT and mobile endpoints.
Source: SecurityWeek
Hackers trick Meta’s AI support bot to hijack high‑profile Instagram accounts
Attackers exploited a “confused deputy” weakness in Meta’s AI support assistant to seize Instagram accounts by having the bot link profiles to attacker‑controlled emails. The incident, which led to brief takeovers of notable accounts, underscores how AI‑driven support workflows can introduce new social‑engineering and authorization risks.
Source: SecurityWeek
19-year-old Linux flaw (CIFSwitch) enables local root; PoC released
A long‑standing Linux kernel vulnerability dubbed CIFSwitch allows low‑privileged users to escalate to root on affected systems. With publicly available proof‑of‑concept code and multiple distributions impacted, defenders should prioritize kernel and cifs-utils updates and restrict untrusted local access paths.
Source: SecurityWeek
Inspector general: NIST’s NVD backlog undermined vulnerability tracking
A federal inspector general found NIST’s National Vulnerability Database became ineffective as its backlog of unprocessed CVEs swelled from 13,000 to over 27,000 by end‑2025. The report warns the delays eroded public trust and utility, pushing organizations to diversify vuln‑intel sources while NVD remediation efforts proceed.
Source: The Record
You May Also Be Interested In...
The Server Seizure That Affects Also Iran’s Cyber Operations
Dashlane Discloses Brute-Force Attack; Limited Encrypted Vault Downloads