May 20, 2026
Categories
CISA credential leak raises alarms, and Capitol Hill demands answers
Skip to main content A researcher who found a repository…
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
Skip to main content Verizon’s annual Data Breach Investigations Report…
Mini Shai-Hulud returns, compromising hundreds of npm packages
Skip to main content Another malware wave is washing through…
Microsoft disrupts cybercrime service that abused software verification systems en masse
Skip to main content Fox Tempest, a financially-motivated threat group,…
Drupal critical update to fix bug with high exploitation risk
Drupal has announced a "core security release" scheduled for later…
Exploit released for new PinTheft Arch Linux root escalation flaw
A recently patched Linux privilege escalation vulnerability now has a…
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub has confirmed that roughly 3,800 internal repositories were breached…
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows…
GitHub investigates internal repositories breach claimed by TeamPCP
Update May 20, 04:17 EDT: GitHub has now confirmed the breach…
Max-severity flaw in ChromaDB for AI apps allows server hijacking
A max-severity vulnerability in the latest Python FastAPI version of…