Security news.
Today's security landscape is marked by significant data breaches, critical vulnerabilities requiring immediate patching, and a rise in sophisticated social engineering attacks. Supply chain risks, particularly within the npm ecosystem, and the growing weaponization of AI by threat actors also remain prominent concerns for developers and IT teams.
Unlimited Technology Systems Breach Impacts 3.8 Million People
Healthcare software company Unlimited Technology Systems reported a data breach from October 2025 affecting over 3.8 million individuals.
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A new campaign has flooded the npm registry with almost 800 malicious packages, using typo-squatting names to distribute a powerful RAT and infostealer targeting Windows, Mac, and Linux systems.
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has patched a pre-authentication reflected cross-site scripting (XSS) flaw (CVE-2026-64638, CVSS 8.9) in its login screen, which can be chained to achieve PHP code execution on the server.
CISA Adds Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037) to KEV Catalog
CISA has added Progress LoadMaster Command Injection Vulnerability, CVE-2026-8037, to its Known Exploited Vulnerabilities Catalog, urging federal agencies to remediate it due to active exploitation.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are deploying a Go-based macOS malware capable of stealing cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials.
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
The data extortion group UNC6671 is conducting vishing attacks, posing as IT help desk staff to target financial, private equity, and professional services employees via their personal phones for SaaS data theft.
Levi Strauss & Co. Says Hackers Stole Corporate Data in Cyberattack
Levi Strauss & Co. disclosed that hackers used social engineering to compromise three employees, gaining access to and stealing corporate data from their machines.
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code, present since 2008, allows local users to gain root privileges and escape containers; fixes have been released in recent stable kernels.