Aggregator
Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap Report
New York, United States, May 19th, 2026, CyberNewswire New research shows identity dark matter continues to expand and erode enterprise identity, resulting in a fragile foundation for agent AI readiness and adoption Orchid Security, the company solving identity at its core, today released its Identity Gap: 2026 Snapshot report, revealing that the majority of enterprise […]
The post Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap Report appeared first on Cyber Security News.
Microsoft Edge security advisory (AV26-476)
600+ npm Packages Compromised in New Mini Shai-Hulud Supply Chain Attack
A sophisticated npm supply chain campaign dubbed Mini Shai-Hulud has claimed over 600 package versions overnight, with security researchers at Socket and Endor Labs identifying 639 compromised package versions across 323 unique packages in the latest wave. The bulk of the activity targeted the @antv ecosystem, alongside packages under @lint-md, @openclaw-cn, and @starmind scopes. Malicious […]
The post 600+ npm Packages Compromised in New Mini Shai-Hulud Supply Chain Attack appeared first on Cyber Security News.
Nirvasa allegedly breached: 3.5K healthcare platform user records advertised for sale
Microsoft представила Cloud-Initiated Driver Recovery — автоматический откат неудачных драйверов через облако
Bug 悬赏项目被 AI 报告淹没
Mini Shai-Hulud returns, compromising hundreds of npm packages
Another malware wave is washing through open-source software repos, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools and CI pipelines.
The post Mini Shai-Hulud returns, compromising hundreds of npm packages appeared first on CyberScoop.
CVE-2025-70950 | gohttp 34ea51 path traversal
CVE-2026-44159 | Tyler TID-L default credentials
CVE-2026-47100 | FunnelKit Funnel Builder for WooCommerce Checkout up to 3.15.0.3 Public Checkout Endpoint authorization
CVE-2026-34883 | Portrait Dell Color Management Application up to 3.6.x Link CCFLFamily_07Feb11.edr symlink
CVE-2026-45557 | Technitium DNS Server up to 14.x amplification
CVE-2025-51427 | ModelScope 1.25.0 Module privilege escalation (EUVD-2025-209897)
CVE-2026-8711 | F5 NGINX JavaScript up to 0.9.8 HTTP ngx.fetch heap-based overflow (K000161307)
CVE-2026-43634 | HestiaCP up to 1.9.4 less trusted source (EUVD-2026-30935)
CVE-2026-2587 | Eclipse Glassfish up to 7.0.x/8.0.0 Gadget expression language injection
CVE-2026-2586 | Eclipse Glassfish 7.1.0/8.0.0 Administration Console code injection (EUVD-2026-30939)
Hackers Hijacking Four-Faith Industrial Routers for Botnet Activity
Hackers are actively exploiting Four-Faith industrial routers to build botnets, leveraging a critical vulnerability identified as CVE-2024-9643. Security researchers from CrowdSec report a sharp rise in exploitation attempts targeting these devices, signaling a shift from initial probing to large-scale abuse. CVE-2024-9643 is a critical authentication bypass flaw affecting Four-Faith F3x36 industrial cellular routers. The vulnerability […]
The post Hackers Hijacking Four-Faith Industrial Routers for Botnet Activity appeared first on Cyber Security News.
Compromised GitHub Action Exfiltrates Workflow Credentials to Attacker Domain
A widely used GitHub Action called actions-cool/issues-helper has been compromised, with every version tag in the repository silently redirected to a malicious commit. The attack places stolen CI/CD pipeline credentials directly in the hands of an attacker, raising serious concerns for development teams around the world that rely on this action in their automated workflows. […]
The post Compromised GitHub Action Exfiltrates Workflow Credentials to Attacker Domain appeared first on Cyber Security News.