Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Today’s signal The Hacker News recently reported Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw. Published context: June 15, 2026. Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS softwar ...

June 15, 2026 · 3 min · David Gomez

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Today’s signal The Hacker News recently reported Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication. Published context: June 13, 2026. Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. “In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user ...

June 14, 2026 · 3 min · David Gomez

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

Today’s signal The Hacker News recently reported GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks. Published context: June 11, 2026. GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the “npm install” command to trigger the execution of malicious code using npm lifecycle hooks. “Npm install” is used to download a ...

June 14, 2026 · 3 min · David Gomez

Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

Today’s signal The Hacker News recently reported Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE. Published context: June 10, 2026. A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrar ...

June 13, 2026 · 3 min · David Gomez

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

Today’s signal The Hacker News recently reported ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities. Published context: June 11, 2026. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory un ...

June 12, 2026 · 3 min · David Gomez

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Today’s signal The Hacker News recently reported Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities. Published context: June 10, 2026. Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It’s tracked as CVE-2026- ...

June 11, 2026 · 3 min · David Gomez

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Today’s signal The Hacker News recently reported Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now. Published context: June 9, 2026. Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome’s JavaScript and WebAssembly engine. “Out-of-bounds read and write in V8 in Goog ...

June 10, 2026 · 3 min · David Gomez

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Today’s signal The Hacker News recently reported IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks. Published context: June 5, 2026. Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer “scrapes every secret it can find on a developer’s machine, hides be ...

June 8, 2026 · 3 min · David Gomez

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Today’s signal The Hacker News recently reported OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack. Published context: June 1, 2026. Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for d ...

June 1, 2026 · 3 min · David Gomez

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Today’s signal The Hacker News recently reported AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites. Published context: May 27, 2026. Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites. “This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations,” Microsoft Defen The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

May 30, 2026 · 3 min · David Gomez

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

Today’s signal The Hacker News recently reported Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels. Published context: May 29, 2026. The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. “Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fak ...

May 29, 2026 · 3 min · David Gomez

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

Today’s signal The Hacker News recently reported GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure. Published context: May 27, 2026. CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions. “Since at least early 2025, GlassWorm operators have systematically The reason this matters is simple: buyers are paying attention to speed, operational resilience, and credible technical execution. A trending story can create awareness, but the business question is what a team should do with that attention. ...

May 27, 2026 · 3 min · David Gomez