OpenAI confirmed that a TanStack-related supply chain compromise led to two employee devices being breached and credentials from internal code repositories being exposed. The TeamPCP group reportedly abused weaknesses in the package publishing process, underscoring the growing risk from poisoned open-source dependencies. Organizations should audit dependency chains, rotate exposed secrets, and harden publishing workflows.
Source: Security Affairs
U.S. CISA adds Microsoft Exchange Server flaw to Known Exploited Vulnerabilities catalog
CISA added CVE-2026-42897 (CVSS 8.1) affecting Microsoft Exchange Server to its KEV catalog, indicating active exploitation in the wild. Microsoft has warned organizations and urged immediate mitigations, making swift patching and monitoring for post-exploitation activity a priority for Exchange admins.
Source: Security Affairs
PoC code drops for critical NGINX vulnerability dating back to 2008
Exploit proof-of-concept code has been released for a critical-severity NGINX flaw introduced in 2008 and patched this week in both open source NGINX and NGINX Plus. With public PoC now available, defenders should prioritize updates and review exposure of internet-facing NGINX instances.
Source: SecurityWeek
Russian APT Turla evolves Kazuar into stealthy P2P botnet for long-term access
Turla has upgraded its Kazuar backdoor into a modular peer-to-peer botnet aimed at persistence and evasion. According to Microsoft researchers, the redesign enables stealthy, long-term control of compromised systems, complicating takedowns and detection by traditional network monitoring.
Source: Security Affairs
Grafana discloses GitHub token breach, codebase accessed amid extortion attempt
Grafana said an unauthorized party obtained a token that allowed access to its GitHub environment and the download of its codebase. The company reported no customer data exposure or impact to customer systems, but the incident highlights the risk of token theft and repository access in supply chains.
Source: TheHackerNews
Pwn2Own Berlin 2026 uncovers 47 zero-days as DEVCORE crowned Master of Pwn
Researchers at Pwn2Own Berlin disclosed 47 unique zero-day vulnerabilities across a broad set of targets, with total awards reaching $1.298 million. Expect a wave of vendor patches and advisories; enterprises should track updates closely and prioritize remediation for internet-facing and high-impact products.
Source: Security Affairs
Active skimming: Funnel Builder plugin exploited to steal WooCommerce payment data
A critical flaw in the Funnel Builder WordPress plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages, enabling payment card skimming. Sansec detailed the campaign; there is no CVE yet, so site owners should disable or update the plugin immediately and scan for skimmer artifacts.
Source: TheHackerNews
You May Also Be Interested In...
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations (Symantec Connect)Microsoft Changes ‘Most Windows Devices’ In June—Update Yours Now (Forbes Security)
Critical ‘Claw Chain’ Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk (HackRead)