News

Miasma Returns

Miasma Returns: Leo Platform npm Packages Hit in New Shai-Hulud Supply Chain Wave

The CyberSec Guru

A compromised developer account infected 23 Leo Platform npm packages with Miasma malware, using Phantom Gyp binding.gyp execution to compromise 320+ GitHub repositories. Full IOC list inside

Deutsche Bahn GSM-R Outage

Germany’s Entire Rail Network Went Dark Last Night. Here’s What Happened.

The CyberSec Guru

A GSM-R communications failure brought every Deutsche Bahn train in Germany to a halt late Tuesday. Here's what happened, what's still unknown, and why it matters

Eight-year-old Samsung Knox flaw

Eight-year-old Samsung Knox flaw exposed Galaxy devices to kernel attacks

The CyberSec Guru

Samsung patched CVE-2026-20971, a long-running Knox PROCA use-after-free flaw that affected Galaxy devices and could lead to kernel memory corruption

KDDI Data Breach

KDDI Breach Exposes Up to 14.22 Million Email Records Across Six Japanese ISPs

The CyberSec Guru

KDDI's 2026 data breach exposed up to 14.22M email credentials across six ISPs - BIGLOBE, @nifty, JCOM, and more. What happened and what's next

CVE-2026-55200 Critical libssh2 RCE Flaw

A critical flaw in libssh2 puts SSH clients at remote code execution risk

The CyberSec Guru

CVE-2026-55200 is a CVSS 9.2 heap overflow in libssh2 enabling pre-auth RCE on all versions through 1.11.1. Fix: commit 97acf3d

Tata Electronics Breach

Tata Electronics Confirms Cyberattack as World Leaks Posts 630GB of Alleged Apple and Tesla Trade Secrets

The CyberSec Guru

Tata Electronics confirmed a cyberattack after World Leaks posted 630GB of alleged Apple and Tesla files including iPhone specs and Tesla trade secrets

Cloudflare Down Fiber Cut Breaks Internet

Cloudflare Down: Fiber Cut in Eastern North America Takes Half the Internet With It

The CyberSec Guru

Cloudflare is down today after a fiber cut in Eastern North America. X, Zoom, Google, AWS and more are affected. Here's what happened and why

Mythos NSA Breach Claim

The Mythos/NSA Breach Claim: What’s Actually Confirmed

The CyberSec Guru

Senator Warner says the NSA director claims Mythos breached classified systems in hours. Here's what's confirmed, what Anthropic disputes, and what's still unverified

GentleKiller

Inside GentleKiller: A Technical Deep-Dive into the Gentlemen RaaS EDR-Killer Supply Chain

The CyberSec Guru

A technical breakdown of GentleKiller, the BYOVD-based EDR killer Gentlemen ransomware builds and distributes to affiliates - variants, drivers, IOCs, and detection

Squidbleed CVE-2026-47729

Squidbleed (CVE-2026-47729): A 29-Year-Old Heartbleed Hiding in Plain Sight

The CyberSec Guru

Squidbleed (CVE-2026-47729): a 29-year-old heap overread in Squid Proxy leaks HTTP Authorization headers across users. Breakdown, PoC, and patch