Three New Threats Hit Internet Infrastructure: Apache RCE, Edge Password Leak, and MicroStealer Malware

Apache HTTP Server, Microsoft Edge, and a new MicroStealer malware each pose distinct threats, from remote code execution to credential theft and targeted sector attacks.

The Latest

Breaking News and Alerts

New Supply Chain Worm Hits SAP npm Packages, Targets Developer Secrets

The Mini Shai-Hulud worm uses a Bun runtime bootstrap to silently harvest credentials from developer machines, cloud platforms, and AI coding tools before npm install completes.

Spotlight

Cybersecurity Profiles and Stories

MOVEit Automation Patches Critical Backend Flaws Allowing Full Server Takeover

Two critical MOVEit Automation vulnerabilities discovered by Airbus SecLab researchers allow unauthenticated attackers to bypass authentication and escalate privileges to full administrative control.

Rogue DHCP Server Attack Can Fully Compromise FreeBSD Systems

The flaw allows attackers on the same local network to inject commands into the dhclient configuration file through unescaped double quotes in BOOTP responses.

Mass Email Floods Precede Fake Teams IT Support in New Wave of Breaches

Security researchers warn that email bombing, which triggers panic, is the entry point for fake IT support calls that achieve a 72 percent success rate.

Active Exploitation of Critical cPanel and WHM Authentication Bypass Confirmed

CISA warns that CVE-2026-41940, an authentication bypass in cPanel and WHM, is being actively exploited, giving attackers full administrative control over web hosting environments.

Features

Research and Thought Leadership