Major Security Flaw In GitHub Enables Remote Code Execution Across Millions of Repositories post, april 28, 2026april 29, 2026 A critical vulnerability discovered within GitHub’s internal infrastructure has raised serious concerns across the global software development community, after researchers revealed it could allow attackers to execute arbitrary code on backend systems using a single command. The flaw, tracked as CVE-2026-3854, was identified by Wiz Research and affects both GitHub’s… Continue Reading
Checkmarx Investigates Dark Web Data Leak Following Supply Chain Cyberattack post, april 27, 2026april 29, 2026 Israeli application security firm Checkmarx has confirmed that data linked to its internal systems has surfaced on the dark web, following a sophisticated supply chain cyberattack first detected on March 23, 2026. The company says its investigation is ongoing, as cybersecurity experts warn the incident could have wider implications for… Continue Reading
Home security giant ADT data breach affects 5.5 million people post, april 27, 2026april 29, 2026 The ShinyHunters extortion group stole the personal information of 5.5 million individuals after breaching the systems of home security giant ADT earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1874 as American District Telegraph, ADT is the oldest and largest home security company… Continue Reading
Critical Vulnerability Exposes Linux Systems To Root-Level Takeover post, april 25, 2026april 29, 2026 A newly disclosed security flaw affecting Linux systems has raised fresh concerns about the integrity of core package management infrastructure, after researchers revealed that a vulnerability lurking for over a decade could allow attackers to escalate privileges and gain root-level control. The flaw, dubbed “Pack2TheRoot,” has been formally tracked as… Continue Reading
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches post, april 24, 2026mei 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency’s Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. FIRESTARTER, per CISA and the U.K.’s National Cyber Security Centre (NCSC), is assessed to be a backdoor… Continue Reading
North Korea’s Lazarus Targets macOS Users via ClickFix post, april 24, 2026april 29, 2026 North Korea’s Lazarus Group is using ClickFix attacks to launch cyberattacks using novel macOS malware. That’s according to security vendor Any.Run, which on April 21 published research concerning a new nation-state threat campaign. Authored by offensive security expert and Birmingham Cyber Arms founder Mauro Eldritch, the report covers a wave… Continue Reading
Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of “Highly Destructive” Wiper post, april 24, 2026april 29, 2026 The mystery around a cyberattack that struck Venezuela’s state-owned oil company in December is growing, following an announcement by researchers this week that they had discovered a “highly destructive” wiper program that appears to have been designed to target the oil company and may have been used in the December… Continue Reading
Firestarter malware survives Cisco firewall updates, security patches post, april 24, 2026april 29, 2026 Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. The backdoor has been attributed to a threat actor that Cisco Talos tracks internally as UAT-4356,… Continue Reading
Palantir Employees Are Starting to Wonder if They’re the Bad Guys post, april 23, 2026april 29, 2026 It took just a few months of President Donald Trump’s second term for Palantir employees to question their company’s commitments to civil liberties. Last fall, Palantir seemed to become the technological backbone of Trump’s immigration enforcement machinery, providing software identifying, tracking, and helping deport immigrants on behalf of the Department of Homeland Security, when current and… Continue Reading
New Lotus data wiper used against Venezuelan energy, utility firms post, april 21, 2026april 24, 2026 A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. The malware was uploaded to a publicly available platform in mid-December from a machine in Venezuela and has been analyzed by researchers at Kaspersky. Continue Reading