A new variant of the SHub macOS infostealer has been discovered that tricks users into believing they need to install a security update. Using AppleScript, this malware presents a fake update message, which, when interacted with, leads to the installation of a backdoor on the user's system. This malicious software primarily targets macOS users, potentially compromising their personal information and system integrity. The ability to deceive users with a legitimate-looking update notice makes this variant particularly concerning. It underscores the need for users to be vigilant about unexpected prompts and verify updates directly from Apple's official channels.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Recent vulnerabilities in the OpenClaw framework, which is gaining popularity for AI agent deployments, have been patched after being discovered. These flaws could allow attackers to steal user credentials, escalate their access privileges, and maintain control over affected systems. Organizations using OpenClaw should be particularly vigilant, as these vulnerabilities pose serious risks if exploited. The issue underscores the importance of keeping software up to date to prevent unauthorized access and data breaches. Users are encouraged to apply the latest security patches to safeguard their deployments.
A serious vulnerability has been discovered in F5 NGINX, a widely used web server technology that powers about one-third of all websites globally. This vulnerability is currently being exploited by attackers, raising alarms among cybersecurity experts. The issue poses a significant risk to countless websites and web applications that rely on NGINX for handling web traffic. Organizations using NGINX should take immediate action to assess their systems and implement necessary security measures to protect against potential attacks. The urgency of this situation is underscored by the fact that the vulnerability is actively being targeted in the wild, making prompt remediation essential to prevent data breaches and other malicious activities.
Grafana has confirmed a breach involving a compromised GitHub token that allowed attackers to access its source code. The incident came to light when the extortion group Coinbase Cartel claimed responsibility and listed Grafana on a leak site on May 15. Fortunately, Grafana Labs stated that no customer data or systems were compromised during this breach. The exposure of source code can pose risks to the security of future updates and features, as it may enable malicious actors to find and exploit vulnerabilities. Companies need to ensure robust token management practices to prevent similar incidents in the future.
The recently leaked Shai-Hulud malware is being used in new attacks targeting the Node Package Manager (npm) index. Over the weekend, several infected packages appeared on npm, raising concerns among developers and users who rely on the platform for JavaScript libraries. This malware is designed to steal sensitive information, which poses a significant risk to developers and organizations that integrate third-party packages into their projects. As this situation unfolds, it is crucial for users to be vigilant and cautious about the packages they download and use. The emergence of this malware highlights the ongoing risks associated with software supply chains and the need for enhanced security measures.
SCM feed for Latest
A recent report from F-Secure indicates that online scams are becoming more prevalent, with 56% of consumers experiencing scam attempts at least once a month in 2025. The rise in these scams is attributed to advances in artificial intelligence, which scammers are using to create more sophisticated and convincing attacks. This trend poses significant risks for individuals, as it increases the likelihood of falling victim to fraud. Consumers need to be vigilant and informed about the evolving tactics used by scammers to protect their personal and financial information. The report serves as a warning to both users and businesses to enhance their security measures and awareness around online scams.
SCM feed for Latest
A recent report from NordVPN reveals that stolen payment card details from the UK are being sold on dark web marketplaces for as little as $12. More comprehensive digital identity packs, which typically include bank cards and personal identification information, are priced around $40. This raises significant concerns for individuals whose data may have been compromised, as it suggests that personal information is readily available to cybercriminals. The accessibility and low cost of these stolen data sets make it easier for malicious actors to commit fraud or identity theft. Users need to be vigilant about protecting their personal information and consider monitoring their financial accounts for any suspicious activity.
Cybercriminals are targeting fans and businesses during the FIFA World Cup with scams involving fake ticketing, accommodation, and transportation apps. These fraudulent platforms trick users into providing sensitive login information or result in financial losses. As excitement builds for the event, fans are particularly vulnerable, often rushing to secure tickets or accommodations without verifying the legitimacy of the sources. This trend underscores the necessity for increased vigilance among users, who need to ensure they are using official channels and services. Awareness of these scams is essential to protect personal information and financial resources.
Recent reports indicate that Iran has expanded its cyber offensive by targeting automatic tank gauge (ATG) systems, which are often connected to the Internet. Security experts have long warned that these systems can be vulnerable to tampering, allowing malicious actors to manipulate fuel tank operations. This poses significant risks not only to the oil and gas sector but also to the safety and security of critical infrastructure. The attack raises concerns about the broader implications of cyber warfare, particularly as these systems are vital for monitoring and managing fuel supplies. As cyber threats evolve, industries must prioritize securing their Internet-connected devices to prevent such breaches.
SCM feed for Latest
Security experts at Cyera have discovered four vulnerabilities in the OpenClaw AI agent, collectively termed Claw Chain. These issues affect all versions of OpenClaw released before April 23, 2026, putting thousands of servers at risk. The vulnerabilities could potentially allow attackers to exploit systems running outdated versions of the software, which is significant given the widespread use of OpenClaw in various applications. Organizations using OpenClaw should prioritize updating their systems to the latest version to prevent any potential exploitation. This situation serves as a reminder of the importance of keeping software up to date to protect against emerging threats.
A security researcher named Andreas Makris has revealed that thousands of Yarbo robotic lawnmowers are vulnerable due to the use of identical default passwords. These lawnmowers, which are equipped with cameras, GPS, and AI mapping, are sold in over 30 countries. The identical default passwords create a significant security risk, as anyone with knowledge of these passwords could potentially access and control the devices remotely. This situation raises concerns about user privacy and safety, especially given the devices' capabilities to capture images and navigate outdoor spaces. Manufacturers need to address this issue urgently to protect users from potential unauthorized access and data breaches.
SCM feed for Latest
The REMUS infostealer has evolved into a sophisticated malware-as-a-service platform, according to Flare's analysis of multiple posts from early 2026. This development cycle, which resembles that of structured software companies, indicates that REMUS is becoming increasingly advanced and accessible for cybercriminals. The platform allows attackers to easily deploy the malware, making it a significant concern for users and organizations alike. With its growing capabilities, REMUS poses a real threat to personal and corporate data security. As this malware continues to evolve, companies need to be vigilant and take steps to protect themselves from potential breaches.
Infosecurity Magazine
Interpol has conducted a significant crackdown on cybercrime in the Middle East and North Africa, resulting in over 200 arrests across 13 countries. This operation targeted various forms of cybercrime, including online fraud and identity theft, affecting numerous individuals and businesses in the region. By coordinating efforts among member countries, Interpol aims to disrupt criminal networks that exploit digital platforms for illegal activities. The operation reflects a growing recognition of the need for international cooperation in combating cyber threats, which can have far-reaching consequences for both the economy and public safety. The arrests are a clear message that cybercrime will not be tolerated, and authorities are committed to enhancing security in the digital space.
Hackread – Cybersecurity News, Data Breaches, AI and More
Government-backed hackers have reportedly exploited Cloudflare's storage services as part of a Malaysian espionage campaign. This operation involved the use of concealed command and control (C2) systems to facilitate data exfiltration. The attackers' methods indicate a sophisticated approach, leveraging legitimate cloud infrastructure to avoid detection. This incident raises significant concerns about the security of cloud services and the potential for state-sponsored cyber activities to target sensitive data. Organizations using Cloudflare or similar services should remain vigilant and review their security measures to protect against such threats.
Help Net Security
A serious vulnerability in NGINX, identified as CVE-2026-42945 and nicknamed NGINX Rift, is currently being exploited by attackers. Disclosed last week, this flaw allows attackers to send specially crafted HTTP requests to vulnerable NGINX servers, potentially leading to denial-of-service conditions and even unauthenticated remote code execution. NGINX is the most widely used web server, meaning a large number of websites and applications could be at risk. Security researcher Patrick Garrity highlighted the urgency of addressing this vulnerability as it poses significant risks to web services that rely on NGINX. It's crucial for administrators to take immediate action to protect their systems from these exploits.