Category Archives: Threat Alerts
Nx Console Attack: GitHub Source Code Breached via Malicious VS Code Extension
A major supply-chain Nx Console attack exploited a compromised VS Code extension to breach GitHub internal repositories, exposing sensitive developer credentials. Continue reading
Microsoft Zero-Day Exploits: Emergency Patches Issued After Nightmare-Eclipse Leaks
Active exploitation of new Microsoft zero-day exploits leaked by a disgruntled researcher has forced urgent Windows Defender patches and BitLocker security mitigations. Continue reading
Kali365 Phishing: FBI Warns of Microsoft 365 Token Hijacking
The FBI has issued an alert regarding the Kali365 phishing toolkit, which bypasses MFA by hijacking Microsoft 365 tokens via legitimate device code flows. Continue reading
Mini Shai-Hulud Worm: TeamPCP Targets GitHub and npm
The Mini Shai-Hulud worm has launched a massive software supply chain campaign, targeting GitHub and npm registries to harvest credentials and exfiltrate corporate data. Continue reading
Fox Tempest Malware-Signing Service Disrupted by Microsoft
Microsoft has dismantled the prolific Fox Tempest malware operation, a specialized service that enabled major ransomware gangs to bypass Windows security mechanisms. Continue reading
BlackFile Cluster: The Rise of Prime Extortion Tactics
Cybersecurity researchers have identified the BlackFile Cluster, a group utilizing Prime Extortion tactics like vishing and swatting to bypass traditional ransomware encryption. Continue reading
M5 Silicon Exploit: AI-Assisted ‘Claw Chain’ Breaches Apple Kernel
Researchers have revealed the first M5 silicon exploit, a sophisticated ‘Claw Chain’ attack developed using AI to bypass Apple’s advanced hardware-level memory protection. Continue reading
MiniPlasma Zero-Day Exploit Released for Windows 11 and Server
A rogue security researcher has publicly released a working MiniPlasma zero-day exploit, allowing local privilege escalation to SYSTEM level on fully patched Windows installations. Continue reading
Grafana Security Breach: Codebase Stolen and Extortion Attempt
A significant Grafana security breach occurred on May 17, 2026, when an attacker used a stolen GitHub token to exfiltrate the company’s entire codebase and demand a ransom. Continue reading