Research
-
China-linked JDY botnet grows to more than 1,500 devices, researchers say
Researchers say the China-linked JDY botnet has grown to more than 1,500 compromised SOHO and IoT devices and is being used to scan exposed services and collect reconnaissance data for follow-on targeting.
-
Unpatched Langflow flaw under active exploitation, researchers say
An unpatched Langflow flaw tracked as CVE-2026-5027 is being actively exploited, researchers say. The bug can allow arbitrary file writes, and about 7,000 instances are exposed online.
-
Browser-based FROST attack can infer site visits from SSD timing
Researchers at Graz University of Technology say a browser-based attack called FROST can infer site visits and app launches from SSD timing, reaching 88.95% accuracy in one macOS test and working without native code or a permission prompt.
-
Six protobuf.js flaws can expose Node.js apps to code execution, denial of service
Six vulnerabilities in protobuf.js could enable remote code execution or denial of service in Node.js apps, according to a Cyera technical analysis. Patches are available for affected protobufjs and protobufjs-cli releases.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
Russia-Aligned Hackers Keep Exploiting WinRAR Flaw to Target Ukraine
Russia-aligned hacking groups have kept exploiting a patched WinRAR flaw against Ukrainian organizations, using crafted archives, hidden payloads and stolen browser data in campaigns that researchers said remained active into 2026.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.
-
China-nexus group used BSD variant of BRICKSTORM in long-running intrusion, Volexity says
A China-nexus group used a BSD variant of BRICKSTORM, PLENET and AGENTPSD in a long-running intrusion against Linux systems, according to a Volexity technical analysis that traced activity through a victim, an MSP and a NAS device.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.









