A malicious PyPI package, hermes-px, that masquerades as a “Secure AI Inference Proxy” while secretly stealing user prompts and abusing a private university AI service. Marketed as an OpenAI-compatible, Tor-routed proxy requiring no API keys, the package actually hijacks a…
Category: EN
CVE-2026-35616: FortiClient EMS Flaw Under Active Exploitation
A critical FortiClient EMS vulnerability (CVE-2026-35616) is under active exploitation, allowing unauthenticated attackers to bypass API protections. The post CVE-2026-35616: FortiClient EMS Flaw Under Active Exploitation appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…
The State of AI Risk Management in 2026 Reveals a Growing Confidence Gap
A new report highlights growing gaps between perceived AI visibility and actual risk. The post The State of AI Risk Management in 2026 Reveals a Growing Confidence Gap appeared first on eSecurity Planet. This article has been indexed from eSecurity…
Attackers Exploit RCE Flaw as 14,000 F5 BIG-IP APM Instances Remain Exposed
Over 14,000 F5 BIG-IP APM instances remain exposed online, as attackers actively exploit a critical remote code execution flaw CVE-2025-53521. Over 14,000 F5 BIG-IP APM instances remain exposed online, with attackers actively exploiting the critical remote code execution vulnerability CVE-2025-53521…
Samsung to Shut Down Its Messaging App, Switch to Google Messages in July
Samsung will discontinue its Messages app in July 2026, pushing users to Google Messages with RCS, AI, and security upgrades. The post Samsung to Shut Down Its Messaging App, Switch to Google Messages in July appeared first on TechRepublic. This…
Convicted spyware maker Bryan Fleming avoids jail at sentencing
The pcTattletale founder escapes a custodial sentence following the first successful prosecution of a spyware maker in the U.S. for over a decade. This article has been indexed from Security News | TechCrunch Read the original article: Convicted spyware maker…
Drift Protocol Hit in $286M Suspected North Korea-Linked Crypto Heist
Hackers have stolen approximately $286 million from Drift Protocol, a leading decentralized perpetual futures exchange on the Solana blockchain, in what security researchers believe may be a North Korea-linked cyberattack. The incident occurred on April 1, 2026, and is already…
Google Brings Lazy Loading to Media Files in New Chrome Release
Google has announced a significant update for its Chrome browser, extending native lazy loading capabilities to audio and video elements. This highly anticipated feature aims to improve web performance, drastically save bandwidth, and offer subtle security benefits by controlling when…
The Google Workspace Blind Spot Every K-12 IT Team Misses
How DeForest School District Gained Visibility into Google Workspace and Transformed Their Security Workflow with Cloud Monitor When you’re responsible for keeping an entire school district’s technology running, “good enough” tools quickly become a problem. For Shelly Broberg, Network and…
How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
The most active piece of enterprise infrastructure in the company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents. In March 2026, the TeamPCP threat actor proved just…
GitHub-Backed Malware Spread via LNK Files in South Korea
Hackers are abusing Windows shortcut files and GitHub to run a stealthy, multi‑stage malware campaign against organizations in South Korea. The operation chains LNK files, PowerShell, and GitHub APIs to deliver surveillance tools while blending into normal enterprise traffic.The campaign…
Die Linke Confirms Data Stolen By Qilin
The Qilin ransomware group recently targeted the German socialist party Die Linke and is now threatening to release stolen information. This article has been indexed from CyberMaterial Read the original article: Die Linke Confirms Data Stolen By Qilin
Good Progress After Northern Ireland Attack
Efforts to restore Northern Ireland’s school computer network are moving forward steadily after a recent cyber attack forced a total system shutdown. This article has been indexed from CyberMaterial Read the original article: Good Progress After Northern Ireland Attack
EU Commission Breach Exposes Data
The European Commission recently suffered a cloud security breach attributed to the threat group TeamPCP, resulting in the exposure of data from 30 different EU entities. This article has been indexed from CyberMaterial Read the original article: EU Commission Breach…
BKA Identifies REvil Ransomware Leaders
German authorities have officially unmasked two high-ranking members of the notorious REvil ransomware gang after an extensive investigation by the Federal Criminal Police Office. This article has been indexed from CyberMaterial Read the original article: BKA Identifies REvil Ransomware Leaders
NY School Data Incidents Rise 72%
New York state schools experienced a significant surge in cybersecurity issues in 2025, with data incident reports jumping 72% over the previous year. This article has been indexed from CyberMaterial Read the original article: NY School Data Incidents Rise 72%
Fake GitHub CI Update Steals Secrets and Tokens
An automated campaign abusing GitHub’s pull_request_target workflow trigger to steal CI/CD secrets at scale. The attacker, using the handle ezmtebo, fired off more than 475 malicious pull requests (PRs) in just 26 hours, impersonating routine CI configuration updates to trick maintainers. The campaign…
Hackers Use Poisoned Axios Package and Phantom Dependency to Spread Cross-Platform Malware
One of the most widely used JavaScript libraries in the world was turned into a weapon on March 30, 2026, when attackers poisoned the Axios npm package and silently deployed malware on developer machines running Windows, macOS, and Linux. With…
Hackers Compromised ILSpy WordPress Domain to Deliver Malware
A new supply chain attack targeting developers after threat actors compromised the official WordPress domain for ILSpy on April 6, 2026. Instead of providing the legitimate software, the hijacked website began redirecting visitors to a malicious webpage to deliver malware.…
Critical Dgraph Database Vulnerability Let Attackers Bypass Authentication
A maximum-severity vulnerability in Dgraph, a popular open-source graph database. Tracked as CVE-2026-34976, this critical flaw carries a perfect CVSS score of 10.0. It allows unauthenticated remote attackers to bypass all security controls, overwrite entire databases, read sensitive server files,…