MiniPlasma Windows Zero-Day Enables SYSTEM Access on Fully Patched Windows 11 PCs 

A new Windows vulnerability called MiniPlasma has recently become a serious concern in the cybersecurity community. Researchers discovered that the exploit can give attackers full SYSTEM-level access on fully updated Windows systems. What makes this issue more dangerous is that the vulnerability reportedly works even after installing the latest May 2026 Windows security updates. Because … Continued

OpenAI Confirms Breach in Major TanStack npm Supply Chain Attack 

OpenAI has confirmed that it was affected by the recent TanStack npm supply chain attack that targeted developers and software companies. The company said two employee devices inside its corporate environment were compromised during the incident. The attack involved malicious code hidden inside trusted npm packages used by developers worldwide. OpenAI stated that it immediately … Continued

Taiwan Rail Cyber Incident Exposes Major Security Weaknesses in Critical Infrastructure 

Taiwan recently faced a serious cybersecurity incident that exposed major security weaknesses in railway communication systems. Reports revealed that a 23-year-old university student managed to interfere with Taiwan’s high-speed rail network using simple radio tools and software available online. The incident quickly gained global attention because it showed how easily critical infrastructure can be affected … Continued

Windows Zero-Day Vulnerabilities Expose BitLocker Bypass and CTFMON Privilege Escalation Risks

Microsoft users and cybersecurity researchers are closely watching two newly revealed Windows zero-day vulnerabilities called YellowKey and GreenPlasma. Reports say these flaws affect Windows 11 and Windows Server 2022 and 2025 systems. The vulnerabilities were publicly disclosed by a researcher known online as Chaotic Eclipse or Nightmare-Eclipse. The same researcher had earlier revealed multiple Microsoft … Continued

PraisonAI CVE-2026-44338 Exploited Within Hours After Public Disclosure

A newly discovered security vulnerability in PraisonAI is being actively targeted by attackers only a few hours after becoming public. The flaw, identified as CVE-2026-44338, is an authentication bypass vulnerability that allows unauthorized users to access protected AI agent functions without logging in. Security researchers said the incident highlights how quickly cybercriminals now react to … Continued

Microsoft Teams Vulnerability Exposes Users to Spoofing Attacks

A newly discovered security vulnerability in Microsoft Teams has raised serious concerns among cybersecurity experts. The flaw could allow attackers to carry out spoofing attacks, where malicious content or communications may appear trustworthy to victims. Microsoft officially disclosed the vulnerability as part of its May 2026 Patch Tuesday security updates. The vulnerability has been identified … Continued

Android Introduces Intrusion Logging to Detect Advanced Spyware Attacks 

Google has introduced a new Android security feature called “Intrusion Logging” to help detect advanced spyware attacks on smartphones. The feature is part of Android’s Advanced Protection system and is mainly designed for users who face higher risks of digital surveillance. This includes journalists, activists, researchers, politicians, and human rights workers. The goal of the … Continued

Instructure Reaches Ransom Agreement After Massive 3.65TB Canvas Data Leak 

A major cybersecurity incident has recently affected Instructure, the company behind the Canvas LMS platform used by schools and universities worldwide. Reports claim that hacker group ShinyHunters stole nearly 3.65 terabytes of data from the system. The incident is being described as one of the biggest cyberattacks ever seen in the education sector. Millions of … Continued

Ollama “Bleeding Llama” Vulnerability Exposes Sensitive AI Server Memory 

A serious cybersecurity vulnerability has recently been discovered in Ollama, a popular open-source AI platform used to run large language models locally. Researchers revealed that the flaw could allow attackers to remotely leak sensitive memory data from affected servers. The vulnerability has been officially identified as CVE-2026-7482 and has also been given the name “Bleeding … Continued

Trellix Breach Sparks Concern After Hackers Claim Source Code Access

Trellix has confirmed that attackers gained unauthorized access to a part of its internal source code repository. The cybersecurity company launched an immediate investigation after discovering the incident. External forensic experts and law enforcement agencies were also involved in the response process. Reports connected the breach to the ransomware group known as RansomHouse. According to … Continued

Newsletter line