A rapidly developing software supply chain attack known as Miasma is one of the latest to move from targeting Red Hat npm packages to infecting numerous Microsoft GitHub repositories. Cloudsmith researchers described the Miasma attack, noting it began after the compromise of the GitHub account of a Red Hat employee, which enabled attackers to use the GitHub OIDC token to deploy malicious packages in the @redhat-cloud-services namespace. Over 30 such compromised packages have been published in the npm registry to facilitate credential, identity, and CI/CD secrets theft. The worm has progressed past package poisoning. According to researchers, Miasma can infect…
Kirsten Doyle
A collaboration between the Dutch National Police and the National Cyber Security Centre (NCSC), has seen a large botnet being shut down. In this operation, 200 servers were identified and addressed as well. These servers controlled millions of infected devices, from computers to phones, and were used to carry out cyberattacks. A security researcher first identified the network and notified the NCSC. The NCSC then alerted the police, and together they dug into the matter. It turns out, the botnet had at least 17 million infected devices. To make matters worse, its 200 controlling servers were right in the Netherlands. …
Palo Alto Networks has alerted customers about the ongoing exploitation of the authentication bypass vulnerability in PAN-OS GlobalProtect. The vulnerability, tracked as CVE-2026-0257, lets unauthenticated actors bypass security measures and set up unsanctioned connections to vulnerable GlobalProtect portals and gateways. A high CVSS score of 7.8 was assigned for this vulnerability. This issue was first disclosed by the company on 13 May, when it said it had seen limited exploitation attempts against unpatched devices. The impacted environments involve PAN-OS and Prisma Access with specific GlobalProtect authentication override settings configured. Both Panorama and Cloud NGFW products are not impacted. Security researchers…
CrowdStrike has shared details of a coordinated operation used to disable the Glassworm botnet, which targets software developers and leverages open-source ecosystems to deploy malware. The CrowdStrike Counter Adversary Operations team, in partnership with Google and the Shadowserver Foundation, took down all four C2 centers of the Glassworm network on 26 May by disrupting all lines of communication between Glassworm’s controllers and infected systems. This prevented additional malicious payloads from being delivered. CrowdStrike said Glassworm was a worldwide attack against software developers via the open-source software ecosystem. The threat actors employed malicious VSCode plug-ins, poisoned Python and npm packages, and…
Threat actors are abusing legitimate RMM tools as a means of creating persistence inside victims’ systems, using the Tiflux RMM tool. Tiflux is a reputable Brazilian software platform used by IT departments and Managed Service Providers (MSPs) for managing IT assets, tickets, teams, and remote monitoring. As reported by Huntress, the campaign is using Tiflux RMM as part of phishing attacks that deploy fake documents followed by remote access tools like Splashtop, UltraVNC, and ScreenConnect. In essence, this attack campaign is among many others in which malefactors have turned to legitimate software to avoid detection. Malspam and fake document lures…
Eight of the leading communications companies in the United States have created a new cybersecurity alliance that aims to improve threat intelligence sharing within the telecommunications industry, amid growing concerns about AI cyberattacks, state-sponsored espionage, and infrastructure attacks. The new cybersecurity partnership, the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), has been launched by eight leading US communications firms, including AT&T, Verizon, T-Mobile, Comcast, Charter Communications, Cox Communications, Lumen Technologies, and Zayo. The telecommunications industry fears that none of the companies have sufficient presence to effectively monitor and respond to increasingly coordinated cyberattacks. According to the founding companies, the increasing involvement of…
For years, passwords were the only thing that mattered for securing our online presence, but the discussion around authentication is evolving rapidly. Passkeys, biometrics, device trust, and adaptive identity management solutions are often cited as the key to the next level of security, while attackers are focusing on directly targeting our identity infrastructure. Session hijacking, multi-factor fatigue attacks, token thefts, and social engineering attacks have shown that enhanced authentication doesn’t mean enhanced security; it just shifts the risks elsewhere. In addition, companies need to find ways to make the authentication process easier for users without compromising the system’s credibility. It isn’t simply about verifying…
According to the 2026 Verizon Data Breach Investigations Report, the threat environment is transforming in terms of speed, scale, and interconnected risk. For the first time in its history, vulnerability exploitation was identified as the top initial access vector, representing 31% of attacks, and the report found that ransomware, third-party attacks, and misuse of AI are all on the rise, both for attack purposes and within organizations. Increasing pressure on security teams includes worsening patch cycles, mobile-focused social engineering campaigns, and shadow AI, all of which increase the risk of source code/data leakage. What underlies all of these trends is a move toward targeting the entire software development process…
The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a threat environment moving much faster than many organizations can reasonably protect themselves against. Based on information collected from more than 31,000 security incidents and over 22,000 confirmed data breaches spanning 145 different countries, the DBIR reveals a changing face to how attackers get in, how fast vulnerabilities are exploited, and the role of AI in both attack and defense. This year’s report makes it clear that vulnerability exploitation has overtaken credential abuse as the top method of initial access to breached networks. Vulnerability exploitation overtakes stolen credentials In past years, compromised credentials were the most common reason…
UK’s National Cyber Security Centre (NCSC) has advised businesses to proceed with caution when considering the implementation of agent-based AI, suggesting that agentic AI represents an entirely different kind of security problem compared to generative AI. According to a recent blog post and global guidance, produced in cooperation with authorities in the US, Australia, Canada, and New Zealand, NCSC advised organisations to “learn to walk before you can run” when using autonomous AI capable of operating without human input. The guidelines show how agentic AI systems increase the attack surface by integrating large language models with external tools, memory, data feeds, and automation processes. As highlighted by the NCSC,…
