CVE-2026-41940: cPanel Authentication Bypass — What Happened and How to Respond

CVE-2026-41940 let unauthenticated attackers bypass cPanel/WHM/Webmail logins entirely — exploits hit before the patch existed. Ports 2082-2096 went dark industry-wide within the hour. Patched versions, response timeline, and audit steps inside.

Continue ReadingCVE-2026-41940: cPanel Authentication Bypass — What Happened and How to Respond

Bleeding Llama: The Ollama CVE That Leaked AI Memory and the Hugging Face Supply Chain Crisis

Two AI security incidents in 48 hours: Bleeding Llama (CVE-2026-7482, CVSS 9.1) leaks full process memory from 300K+ exposed Ollama servers via malicious GGUF files, while a fake OpenAI Privacy Filter on Hugging Face hit #1 trending and delivered a Rust infostealer to 244K+ victims. Verification and patching playbook inside.

Continue ReadingBleeding Llama: The Ollama CVE That Leaked AI Memory and the Hugging Face Supply Chain Crisis

April 2026 Cyber Threat Landscape: Zero-Days, Ransomware, and What Changed

April 2026 was one of the most volatile months in cybersecurity history: Microsoft's 167-flaw Patch Tuesday, exploited SharePoint and IKE zero-days, ransomware at Rockstar and McGraw-Hill, and two CISA emergency directives — everything defenders need to know.

Continue ReadingApril 2026 Cyber Threat Landscape: Zero-Days, Ransomware, and What Changed

Microsoft April 2026 Patch Tuesday: 168 Vulnerabilities, Active Zero-Days, and What You Need to Know

Microsoft's April 2026 Patch Tuesday fixed 168 vulnerabilities — an exploited SharePoint zero-day (CVE-2026-32201), the BlueHammer Defender EoP, and a CVSS 9.8 IKE RCE. Complete breakdown and patching order inside.

Continue ReadingMicrosoft April 2026 Patch Tuesday: 168 Vulnerabilities, Active Zero-Days, and What You Need to Know

Node-IPC Supply Chain Attack: When Your npm Dependencies Turn Hostile (2026)

Three versions of node-ipc (10.1.1-10.1.3) shipped a stealer backdoor - CVE-2026-44338 - harvesting SSH keys, AWS credentials and .npmrc from 1.2M-weekly-download installs via DNS tunneling and HTTPS C2. Technical breakdown and hardening guide.

Continue ReadingNode-IPC Supply Chain Attack: When Your npm Dependencies Turn Hostile (2026)