Recent Advisories

Severity ID Title Vendor Product Date Type
NONE HACKREAD:8FCB67...

Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account_HACKREAD:8FCB67E5B8DC94B34C1007AED8D877F6

32 Red Hat npm packages compromised by Miasma malware expose cloud tokens, CI/CD secrets and developer credentials in supply chain attack.

N/A N/A HACKREAD
NONE MSSECURE:E1EAFC...

Securing CI/CD in an agentic world: Claude Code Github action case_MSSECURE:E1EAFCDAA5DF186F9FDB99A1F9C2ED1C

Microsoft Threat Intelligence discovered that Anthropic's Claude Code GitHub Action could expose CI/CD workflow secrets when AI agents process untr...

N/A N/A MSSECURE
NONE HACKREAD:1FC85E...

Atlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service Users_HACKREAD:1FC85EA1FE1F8DE63B49601B3A576F6F

Atlas Menu Data Breach exposes 64,000 GTA V and CS2 cheat service users, leaking emails, IPs, support tickets and hashed passwords.

N/A N/A HACKREAD
NONE THN:4D2A4B53EC1...

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks_THN:4D2A4B53EC1F983BEA9EEC8241B5079D

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFimSGBOnvlCj_r6fiLdzK6V8DLTIQYjROKxHgQH8QxyRVIL3NDpQe9lBISjqCSjcZNl6VPhHVFtdJ8gPe2F...

N/A N/A THN
HIGH 7.5 H1:3784125

curl: GnuTLS OCSP stapling accepts unrelated SingleResponse (no cert-ID binding)_H1:3784125

## Summary This report describes a **variant** of the publicly disclosed curl vulnerability **CVE-2020-8286** (OCSP stapling verification bypass),...

N/A N/A HACKERONE
NONE THN:A8BF8FBEF42...

Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps_THN:A8BF8FBEF4274F3EC8D5CB9EE11940A3

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimTj2SdhVr1jj9e2RqrAOW9dIsBmuMZJsqWGt6weL0DOfhwYQF_6Hp5B-sYt6ZZEGQB_YPTOW6Xb2x5Jygle...

N/A N/A THN
NONE QUALYSBLOG:60D1...

Advancing Cybersecurity in the Age of Frontier AI: Qualys Steps into Project Glasswing_QUALYSBLOG:60D16A3D311E41CF4392798E379C6F5B

The cybersecurity industry has spent much of the last two years debating how attackers might use AI. That debate matters, but it misses a larger po...

N/A N/A QUALYSBLOG
NONE HACKREAD:1D37B2...

Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords_HACKREAD:1D37B22B6A0B5E80724BF3D61C9DD448

Threat actors are deploying an updated SHub Stealer variant named Reaper that exploits the native macOS Script Editor to bypass OS-level protection...

N/A N/A HACKREAD
NONE SCHNEIER:B1D260...

AI Worm_SCHNEIER:B1D2603916F84F7F7C9F6533DC094D65

Researchers have prototyped an AI-powered internet worm. The coolest thing about the prototype is that it carries its own LLM with it, and runs it...

N/A N/A SCHNEIER
NONE THN:38B4A872A5C...

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework_THN:38B4A872A5CA191303381BD0807C4FBB

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiab_7FEmO4woH_bG4spUNJRFCFvvmpF9ggnhOlkIf7f0Ma7z4oEwL0MxFSe4CstBBQRLFsYxObArJESQWOkw...

N/A N/A THN