Backdoored PyTorch Lightning package drops credential stealer May 4, 2026 A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a credential-stealing payload targeting
Amazon SES increasingly abused in phishing to evade detection May 4, 2026 The Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass standard security
Weaver E-cology critical bug exploited in attacks since March May 4, 2026 Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands.