Cybersecurity 101
What Is Patch Management?
A clear guide to patch management — why it matters, the step-by-step process, the types of patches, common challenges, and proven best practices.
Nation-State Cyber Threats
Seqrite Labs says the Pakistan-aligned group SideCopy likely ran Operation XENOFISCAL, a spear-phishing campaign that hit Afghanistan's Ministry of Finance and provincial finance offices with the open-source Xeno RAT, delivered through a Pashto-language ZIP-and-LNK lure.
Vulnerabilities
CISA added CVE-2024-21182 — an unauthenticated Oracle WebLogic flaw patched in July 2024 — to its Known Exploited Vulnerabilities catalog on evidence of active exploitation. Despite 'RCE' framing elsewhere, CISA describes unauthorized access to WebLogic data; agencies must patch by June 4.
Supply Chain Attack
A compromised Red Hat employee GitHub account pushed a new 'Miasma' build of the Mini Shai-Hulud worm into 32 Cloud Services npm packages. Red Hat says the code was internal-only and never reached customers; any pipeline that installed a poisoned version should rotate its secrets.
Vulnerabilities
Google's June 2026 Android update fixes CVE-2025-48595, an Android Framework integer overflow that Google says may be under limited, targeted exploitation. Because the Framework is the API layer every app touches, the flaw can hand an attacker complete control of an unpatched device.
Malware
Unit 42 documented Operation FlutterBridge, a macOS malvertising campaign that uses hundreds of Google-verified ads to drop FlutterShell — a new backdoor built with Google's Flutter framework that adds shell execution, file manipulation and AI-summarization-based exfiltration to adware.
Artificial Intelligence (AI)
Sophos documented a threat actor using AI agents — including a Claude Opus 4.5 coordinator — to run a lab testing malware against Sophos, CrowdStrike and Microsoft Defender. Notably, the lab's own claims of rising evasion success were not borne out by Sophos's data.
Mobile Security
A single debug setting left enabled in Microsoft's Android Office apps — Word, Excel, PowerPoint, OneNote, Loop and Microsoft 365 Copilot — let any other app on the same device read Microsoft account tokens, per a SecurityWeek exclusive. Microsoft has patched the flaws.
Artificial Intelligence (AI)
Attackers seized high-profile Instagram accounts by exploiting a 'confused deputy' flaw in Meta's AI support bot: they asked it to bind a new email, the bot sent the one-time code to the attacker, and the owner was locked out. Meta has pushed an emergency hotfix.
Cybersecurity 101
The three "zero-day" terms explained — vulnerability, exploit, and attack — how they connect on a timeline, why they are dangerous, and how to defend.
Belgium's national cybersecurity authority warned on May 29 that CVE-2026-41089, a critical pre-auth buffer-overflow RCE in Windows Netlogon, is now being exploited against unpatched domain controllers. Microsoft patched the flaw in its May 12 Patch Tuesday release.
Seqrite Labs disclosed Operation Dragon Weave, a China-aligned cyber-espionage campaign delivering an AdaptixC2 agent against government, research, academic, technology, and financial-services targets in the Czech Republic and Taiwan via spear-phishing ZIPs.
CVE-2026-8732, a CVSS 9.8 flaw in the WP Maps Pro WordPress plugin, lets any unauthenticated attacker mint an administrator account on 15,000 affected sites. Wordfence blocked 2,858 exploitation attempts in a single 24-hour window. Patch is in v6.1.1.
Sekoia documented an FSB-linked Gamaredon campaign whose GammaWorm hides fileless VBScript modules inside NTFS Alternate Data Streams to spy on Ukrainian government, military, and critical-infrastructure targets while leaving almost no trace on disk.
The npm package codexui-android, a remote web UI for OpenAI Codex with 29,000 weekly downloads, has been exfiltrating users' Codex authentication tokens to an attacker server for the past month. The package is still live on npm.
Dashlane confirmed that an external party brute-forced the token check on its new-device-registration flow, and the company's automatic protections suspended targeted accounts. The lockout is the protection working — the news is what attackers went after.
Rapid7's Stephen Fewer disclosed CVE-2026-0826 on June 1 — an unauthenticated stack-based overflow in HP Poly VVX and Trio enterprise VoIP phones with a CVSSv4 of 9.2 — alongside HP firmware fixes released the same morning after a five-month coordinated disclosure cycle.
A clear guide to exploits — what they are, how they differ from vulnerabilities, how they work, the common types, and how to defend against them.
Microsoft Threat Intelligence has named a new npm supply-chain wave the Mini Shai-Hulud campaign. A single maintainer alias, vpmdhaj, published 14 typosquatted packages in four hours that harvest AWS, HashiCorp Vault, npm, and GitHub Actions secrets from CI/CD runners.
Dutch Politie and NCSC-NL took down 200 Netherlands-based servers running Asocks, a residential proxy service built from at least 17 million infected consumer devices. The takedown weakens the IP-reputation assumptions every defender relies on.
A clear guide to the common types of software vulnerabilities — from memory and injection flaws to broken authentication, access control, and misconfigurations.
Obsidian Security published proof-of-concept code on May 30, 2026 for CVE-2026-40933, a CVSS 10.0 remote code execution flaw in Flowise. A malicious chatflow import owns the server. Patch 3.1.0 contains the fix.