News

Miasma Just Went Open Source. Here’s What’s Actually Inside It
The Miasma supply chain worm just went open source. We analyzed the full source code - 5-layer obfuscation, GitHub-as-C2, AI tool hijacking etc

CVE-2026-23111: One Inverted Character in Linux’s nftables Hands Attackers Root
CVE-2026-23111 is a use-after-free in Linux's nftables that lets an unprivileged user escalate to root. Working exploits are public. Here's exactly how it works

Yoti Flagged A Playstation User to Authorities for Running GrapheneOS on their Phone
Sony's age-verification partner Yoti reportedly flagged a GrapheneOS user to authorities. Here's what actually happened and why it matters for everyone

Silent Persistence: How Chinese APT ‘VerdantBamboo’ Spent 18 Months Inside Microsoft 365 Using Custom Malware
Discover how Chinese espionage group UNC5221 (VerdantBamboo) used Brickstorm & Plenet to hide inside Microsoft 365 and MSP networks for over 18 months

Hades Descends to PyPI: Miasma Supply Chain Campaign Spreads via Malicious .pth Startup Hooks
Security researchers detect "Hades," a PyPI branch of the Mini Shai-Hulud / Miasma malware lineage. Over 37 packages compromised via .pth startup hooks.

Miasma Worm Weaponizes AI Coding Agents: Inside the Microsoft Azure and GitHub Supply Chain Attack Campaign
The Miasma worm targets AI coding agents via GitHub. Learn how the campaign compromised Azure durabletask & caused 73 repos to be disabled

Supply Chain Crisis: Over 30 Red Hat npm Packages Hijacked to Spread the Self-Propagating ‘Miasma’ Worm
Over 30 @redhat-cloud-services npm packages have been compromised with 'Miasma', a self-propagating credential-stealing worm. Read analysis

The Meta AI exploit: how a prompt injection flaw bypassed 2FA to steal million-dollar Instagram accounts
A critical Meta AI vulnerability on Instagram allowed hackers to bypass 2FA and hijack high-value OG accounts. Discover how the exploit worked

Critical Gogs RCE Vulnerability: Unpatched 0-Day Sitting Open for Over Two Months
A critical CVSS 9.4 zero-day RCE vulnerability has been found in Gogs. Learn how the git rebase exploit works and how to secure your server today

The TrapDoor Supply Chain Attack: Coordinated Multi-Registry Campaign Hits npm, PyPI, and Crates.io
Inside the TrapDoor supply chain attack. Discover how 34+ packages across npm, PyPI, and Crates.io use AI prompt injection to steal dev secrets





