Ivanti warns of new EPMM flaw exploited in zero-day attacks May 7, 2026 Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day
Australia warns of ClickFix attacks pushing Vidar Stealer malware May 7, 2026 The Australian Cyber Security Center (ACSC) is warning organizations of an ongoing malware campaign using the ClickFix social engineering technique
New PCPJack worm steals credentials, cleans TeamPCP infections May 7, 2026 A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP’s access to the
New Cisco DoS flaw requires manual reboot to revive devices May 7, 2026 Cisco released security updates to fix a Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) denial-of-service (DoS) vulnerability that
Critical vm2 sandbox bug lets attackers execute code on hosts May 7, 2026 A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the
Hackers abuse Google ads for GoDaddy ManageWP login phishing May 7, 2026 A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of