Cisco Systems has disclosed a critical authentication bypass vulnerability, CVE-2026-20093, affecting its Integrated Management Controller (IMC) with a CVSS score of 9.8. This flaw allows unauthenticated remote…
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
On March 20, 2026, a new worm named CanisterWorm was detected compromising numerous NPM packages, following a prior attack on the Trivy scanner. The threat actor, TeamPCP, is believed to be behind both attacks.…
A phishing campaign has been launched against hotels in Europe and Asia, utilizing malicious zip files disguised as guest photos to install malware. Attackers impersonate guests with complaints, tricking hotel employees…