Critical MOVEit Automation Flaw Allows Authentication Bypass, Warns Progress Software

A serious cybersecurity issue has recently been identified in MOVEit Automation, a file transfer solution developed by Progress Software. The vulnerability is tracked as CVE-2026-4670 and has been classified as critical. It allows attackers to bypass authentication and access systems without valid login credentials. This is dangerous because authentication is the first layer of security … Continued

Mini Shai-Hulud Attack Targets SAP npm Packages, Exposes Developer Credentials 

A new cyberattack called “Mini Shai-Hulud” has been discovered and is linked to a group known as TeamPCP. This attack mainly targets software packages used in SAP development environments. Instead of directly hacking systems, the attackers chose a smarter approach by compromising trusted tools. These tools are used daily by developers, which makes the attack … Continued

Poisoned Ruby Gems and Go Modules Target CI/CD Pipelines for Credential Theft 

A new cybersecurity threat has been discovered where attackers are using fake open-source packages to target developers and automated systems. These attacks involve malicious Ruby gems and Go modules that were uploaded online and made to look like trusted libraries. The main goal of this campaign is to steal sensitive credentials and gain unauthorized access … Continued

BlueNoroff’s Fake Zoom Calls Are Turning Victims Into Cyberattack Tools 

A new cyberattack campaign has been discovered involving BlueNoroff, which is known for targeting financial systems. In this case, the group is focusing on people working in the cryptocurrency industry. The attackers are using fake online meetings to trick victims into trusting them. These meetings appear to be real business discussions. However, everything is actually … Continued

Newsletter line