Recent Advisories

Severity ID Title Vendor Product Date Type
NONE THN:A3FCB097A6E...

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack_THN:A3FCB097A6E8D4E706033E5DB5DB8A47

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhatZ2Vkvxd086INLXiuhbRJrli5Ao9hoNajbVq-Xr0HVAS70cCzhRBfM78KEusnBPI1sXyAK5tYrKt55U5mT...

N/A N/A THN
NONE THN:195C111EF2F...

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant_THN:195C111EF2FF8E8AAA5D941FD511A3DE

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWYWOSDRBtv65eOzqdHSuOxXN7BWyBo1EAltLLUTTKGt68GYJ67zn9ixdKIQjTPCgE3P1o09UzrwXzvbopRZ...

N/A N/A THN
NONE THN:ACC3B012B26...

Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff _THN:ACC3B012B2608F7FC56BF4FD84BF33BB

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBSVw_gpnELsdqj1fhZXQ6Jm-ycv8RsT1-Q7vfNeyj0_Sd-keBXqrAA9w7Vz8qt0tKM3yXkVPknx8FtRKBGB...

N/A N/A THN
MEDIUM 5.5 MS:CVE-2026-4367

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing_MS:CVE-2026-4367

{“lastseen”:”2026-06-26T07:47:53″,”description”:””,”published”:”2026-06-25T08:03:...

N/A N/A MSCVE
HIGH 8.8 THN:3AF4D7A4A25...

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks_THN:3AF4D7A4A2521E78D5A57F5ED9C21560

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9SthtlfUvEkaX0iZanYdYTAOV5hgm44yCwHu_3GCaoa11rO-GkO9oc0_qN9JGw2n86dsEsN_sdaYt2ra_4I...

N/A N/A THN
NONE MSSECURE:AA575A...

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access_MSSECURE:AA575A60004644ACAFBF2293B2100746

In this article 1. Attack chain overview 2. Mitigation and protection guidance 3. References 4. Learn more Microsoft Threat Intelligen...

N/A N/A MSSECURE
NONE MSSECURE:A4C90F...

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them_MSSECURE:A4C90F6D8F83B1BF96EC12CDFC5FC84E

In this article 1. The role of infostealers: From credential theft to intrusion 2. StealC: Infostealer for rent 3. Amadey: Malware-as-a-serv...

N/A N/A MSSECURE
NONE MSSECURE:0C0117...

Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms_MSSECURE:0C0117AE434E10AACC147291C44D651A

The endpoint management category is being redefined in real time. Organizations no longer need tools that only inventory devices or enforce configu...

N/A N/A MSSECURE
NONE TALOSBLOG:7A5EA...

Beyond IOCs: AI-enabled threat intelligence_TALOSBLOG:7A5EACBCE90B3C23AAD5D9F502830B62

![Beyond IOCs: AI-enabled threat intelligence](https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/06/threat_...

N/A N/A TALOSBLOG
NONE MALWAREBYTES:A9...

Beware of “Parcel Expert” job offers: They’re parcel mule scams_MALWAREBYTES:A9E730320780F4A3D2DE63A112ACB6A1

A parcel mule scam, also called a reshipping scam, is a fake job offer designed to recruit people into handling stolen goods. It usually starts wi...

N/A N/A MALWAREBYTES