News

Mini Shai-Hulud npm Attack

Mini Shai-Hulud Worm Hits npm: TanStack and Mistral Among 160+ Packages Compromised in Massive Supply Chain Attack

The CyberSec Guru

Full list of 160+ packages compromised by the Mini Shai-Hulud worm, including TanStack, Mistral AI, and UiPath. Technical deep-dive and recovery

Foxconn ransomware breach Nitrogen group

Nitrogen Ransomware Claims 8TB Theft from Foxconn’s Wisconsin Plant

The CyberSec Guru

8TB breach hits Foxconn Wisconsin! Nitrogen ransomware group claims 11 million files stolen, including Apple & Google specs

Malicious “OpenAI Privacy Filter” Hits #1 on Hugging Face: 244K Downloads of Stealthy Infostealer

The CyberSec Guru

A fake OpenAI Privacy Filter repository reached #1 on Hugging Face, tricking 244K users into downloading a Rust-based infostealer. Learn about it

Dirty Frag

Dirty Frag: A Zero-Day With No Patch Just Handed Every Linux Server a Root Shell

The CyberSec Guru

The Dirty Frag Linux vulnerability enables universal root access on Ubuntu, RHEL, and Fedora. With no official patch available, read the analysis

Critical vm2 Sandbox Vulnerabilities

Security Alert: Dozen Critical Vulnerabilities Found in vm2 Node.js Library – Sandbox Escapes Allow Host Takeover

The CyberSec Guru

Over 12 critical vulnerabilities (CVSS 10.0) discovered in vm2 Node.js library allow attackers to escape the sandbox and execute host code.

DENIC .de Outage

Germany Deleted? The DNSSEC Mistake That Took Down .de

The CyberSec Guru

On May 5, 2026, a DENIC DNSSEC error took millions of .de websites offline. Read in-depth technical analysis of the outage that paralyzed Germany's internet

Apache RCE CVE-2026-23918

Millions at Risk: Critical Apache HTTP Server Vulnerabilities Expose Servers to RCE Attacks

The CyberSec Guru

Apache HTTP Server releases version 2.4.67 to fix a critical RCE vulnerability (CVE-2026-23918) and privilege escalation flaws. Upgrade now

Alleged NVIDIA GeForce NOW Data Breach

Alleged NVIDIA GeForce NOW Data Breach: ShinyHunters Claims Millions of Records Compromised

The CyberSec Guru

Alleged NVIDIA GeForce NOW data breach by ShinyHunters. Over millions of user records, including emails and 2FA status, reportedly for sale

CVE-2026-41940 cPanel PoC

Critical cPanel & WHM Zero-Day (CVE-2026-41940) Grants Root Access; PoC Circulates on Dark Web

The CyberSec Guru

A critical authentication bypass (CVE-2026-41940) in cPanel & WHM allows unauthenticated root access. PoC is circulating in dark web forums

WordPress.com Login and Dashboard Down: Users Facing 502 Errors

The CyberSec Guru

WordPress.com is experiencing a major outage affecting login and dashboards. Learn why you're seeing the 502 error and "Whoops" message and how to fix it

12310 Next