Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.

The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLoc… Continue reading Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Posted in Uncategorized

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub on Tuesday said it’s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform’s source code and internal organizations for sale on a cybercrime forum.

“While we current… Continue reading GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

Posted in Uncategorized

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.

The activity, per HUMAN’s Satori Threat Intelligence and Research Team, encompassed 455 malicious Android app… Continue reading Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Posted in Uncategorized

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Drupal has issued an alert stating that it intends to release a “core security release” for all supported branches on May 20, 2026, from 5-9 p.m. UTC.

“The Drupal Security Team urges you to reserve time for core updates at that time because exploits m… Continue reading Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Posted in Uncategorized

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtu… Continue reading SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Posted in Uncategorized

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace.

The extension in question is rwl.angular-console (version 18.95.0), a popular user i… Continue reading Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Posted in Uncategorized