A malicious update to the popular Nx Console VS Code extension (2.2M installs) was used by the TeamPCP group to steal developer credentials and secrets, pivot through CI/CD pipelines, and exfiltrate roughly 3,800 of GitHub’s private repositories. The incident underscores how a single compromised dev tool can cascade across organizations; teams should immediately audit IDE extensions, rotate all tokens/SSH keys, harden CI/CD runners, and enforce least privilege on build secrets.
Source: Help Net Security
Actively exploited Microsoft Defender zero-days added to KEV—patch now
Microsoft and CISA confirmed in-the-wild exploitation of two Microsoft Defender flaws: CVE-2026-41091 (local privilege escalation to SYSTEM via improper link resolution) and CVE-2026-45498 (denial of service). Because these vulnerabilities target endpoint protection itself, defenders should expedite patching, verify Defender engine updates across fleets, and monitor for tampering or unexpected Defender service restarts.
Source: Help Net Security
Cisco Secure Workload flaw earns a perfect 10 CVSS—unauthenticated API access can grant Site Admin
Cisco patched CVE-2026-20223, a critical Secure Workload (Tetration) REST API vulnerability that allows remote, unauthenticated attackers to gain Site Admin privileges due to insufficient validation and authentication. Organizations should apply fixes immediately, review audit logs for anomalous API calls or privilege changes, and restrict management-plane exposure.
Source: SecurityWeek
Europol dismantles “First VPN,” a staple for ransomware crews; users identified
In Operation Saffron, French and Dutch authorities—backed by Europol/Eurojust—seized 33 servers and disrupted First VPN, a crime-focused anonymity service the FBI says supported dozens of ransomware groups. Beyond the takedown, investigators say they can identify many customers, signaling more arrests and adding pressure on criminal infrastructure that has long shielded intrusions and extortion.
Source: SecurityWeek
CISA opens KEV nominations to researchers for faster tracking of exploited bugs
CISA launched a public nomination form allowing researchers, vendors, and industry partners to submit vulnerabilities for inclusion in the Known Exploited Vulnerabilities catalog. The move should shorten time-to-prioritization for defenders, improving patching queues and risk workflows when exploitation evidence emerges outside traditional channels.
Source: The Record by Recorded Future
Deleted Google API keys can stay usable up to 23 minutes—window for data theft and billing abuse
Threat hunters found Google Cloud API keys remain active for an average of 16 minutes (up to 23) after deletion, leaving a gap attackers can exploit to access services like Gemini, BigQuery, and Maps or rack up charges. Teams should proactively rotate keys, monitor key usage post-deletion, apply egress controls, and prefer short-lived service credentials to minimize exposure.
Source: The Register
Alleged Kimwolf IoT botnet operator arrested; faces charges in U.S. and Canada
Authorities arrested a 23-year-old Ottawa man accused of creating and operating the Kimwolf botnet, which reportedly hijacked millions of IoT devices for massive DDoS attacks over the past six months. The case highlights ongoing law-enforcement focus on DDoS-for-hire ecosystems and the persistent risk from poorly secured connected devices.
Source: KrebsOnSecurity
You May Also Be Interested In...
New ‘Showboat’ Linux malware targets telecoms with a SOCKS5 backdoor
Drupal patches highly critical unauthenticated SQL injection (CVE-2026-9082)
Trend Micro Apex One zero-day exploited in the wild gets a fix