TechLogHub Blog — Page 10 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
Hackers Exploit Auth Bypass Flaw in Burst Statistics WordPress Plugin
May 14, 2026

Hackers Exploit Auth Bypass Flaw in Burst Statistics WordPress Plugin

Hackers are exploiting a critical authentication bypass in the Burst Statistics WordPress plugin (CVE-2026-8181), allowing unauthenticated attackers to impersonate admins via REST API and potentially create rogue admin accounts. The flaw was introduced in version 3.4.0 (April 23) and persisted in 3.4.1. Wordfence began tracking on May 8, with thousands of attacks blocked in 24 hours. A patched release, version 3.4.2, arrived on May 12, 2026; users should upgrade or disable the plugin. With about 200,000 sites using Burst Statistics, an estimated 115,000 could still be at risk if they remain on older versions.

By TechLogHub
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (CVE-2026-20182)
May 14, 2026

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks (CVE-2026-20182)

Cisco warns of a critical authentication-bypass flaw in Catalyst SD-WAN Controller and Manager (CVE-2026-20182) being exploited in zero-day attacks to gain admin privileges and manipulate SD-WAN configurations. The vulnerability stems from a faulty peering authentication mechanism, allowing attackers to log in as a high-privileged internal user and access NETCONF. Threat actors were observed exploiting it in May 2026; indicators include rogue peering events and unexpected "Accepted publickey for vmanage-admin" entries. Cisco urges upgrading to fixed software, restricting SD-WAN management access, and reviewing logs; CISA has added the vulnerability to the Known Exploited Vulnerabilities catalog with a patch deadline of May 17, 2026.

By TechLogHub
OpenAI Confirms Security Breach in TanStack Supply Chain Attack
May 14, 2026

OpenAI Confirms Security Breach in TanStack Supply Chain Attack

OpenAI confirms a security breach tied to the Mini Shai-Hulud TanStack supply-chain attack, with two employees’ devices compromised and limited access to a subset of internal repositories. There is no evidence of customer data, production systems, or deployed software being affected; however, code-signing certificates were exposed and rotated as a precaution. macOS OpenAI desktop apps must be updated by June 12, 2026, while Windows and iOS versions are unaffected. The incident underscores the broader risk of software supply-chain attacks across npm and PyPI ecosystems.

By TechLogHub
Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026
May 14, 2026

Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026

Security researchers at Pwn2Own Berlin 2026 racked up more than $523,000 on day one after 24 zero‑days were chained, with Orange Tsai earning $175,000 for a four‑bug sandbox escape on Microsoft Edge. Windows 11 was hacked three times, earning $30,000 per researcher (Angelboy, TwinkleStar03 with the DEVCORE Internship Program, Marcin Wiązowski, and Kentaro Kawane of GMO Cybersecurity). IBM X‑Force XOR’s Valentina Palmiotti collected $20,000 for rooting Red Hat Linux for Workstations and $50,000 for a zero‑day in the NVIDIA Container Toolkit. Other notable wins included k3vg3n’s $40,000 for LiteLLM, NVIDIA Megatron Bridge exploits for $20,000, and OpenAI Codex exploits by Compass Security and maitai of Doyensec for $40,000 each, plus Chroma and LM Studio zero‑days. DEVCORE leads the competition with $205,000, followed by Palmiotti with $70,000. The three‑day event runs May 14–16 at OffensiveCon and will see researchers targeting browsers, servers, and AI/LLM platforms for prizes that could exceed $1,000,000; vendors will have 90 days to patch disclosed flaws.

By TechLogHub
KongTuke hackers now use Microsoft Teams for corporate breaches
May 14, 2026

KongTuke hackers now use Microsoft Teams for corporate breaches

The KongTuke group has shifted to using Microsoft Teams for social engineering to breach corporate networks, delivering ModeloRAT after victims paste a PowerShell command in a Teams chat. Active since April 2026, the operation rotates through multiple Microsoft 365 tenants to evade blocks and uses Unicode tricks to spoof IT staff. ModeloRAT now features a resilient five-server C2, multiple access paths, and enhanced persistence (Run keys, Startup shortcuts, VBScript launchers, scheduled tasks). Recommendations include restricting external Teams federation and using ReliaQuest IOC indicators to hunt for signs of compromise.

By TechLogHub
West Pharmaceutical says hackers stole data, encrypted systems
May 13, 2026

West Pharmaceutical says hackers stole data, encrypted systems

West Pharmaceutical Services says it was the target of a material cybersecurity attack in which data was exfiltrated and some systems were encrypted. The compromise was detected May 4, 2026, with incident response actions including taking systems offline, notifying law enforcement, and engaging external forensics; core shipping and manufacturing systems have been restored and manufacturing partially restarted, but full restoration and the incident's financial impact are still undetermined. The company is working with Palo Alto Networks’ Unit 42, and no ransomware group has claimed responsibility at this time.

By TechLogHub
New critical Exim mailer flaw allows remote code execution
May 13, 2026

New critical Exim mailer flaw allows remote code execution

Exim’s open‑source mail transfer agent has a critical vulnerability (CVE-2026-45185) that allows unauthenticated remote code execution on affected builds (Exim 4.97–4.99.2) compiled with GnuTLS. The bug is a use-after-free during TLS shutdown in BDAT chunked SMTP traffic and can give attackers control over the server; OpenSSL builds are not affected. A patch is available in Exim 4.99.3. The flaw was discovered by Federico Kirschbaum of XBOW, who demonstrated an AI‑assisted PoC exploit, though researchers note humans still play a crucial role. Ubuntu and Debian users should update via their package managers.

By TechLogHub
Windows BitLocker zero-day gives access to protected drives, PoC released
May 13, 2026

Windows BitLocker zero-day gives access to protected drives, PoC released

Security researcher Chaotic Eclipse has released PoCs for two unpatched Windows flaws, YellowKey and GreenPlasma, collectively known as Chaotic Eclipse. YellowKey is a BitLocker bypass that exploits the Windows Recovery Environment to gain shell access on TPM-protected drives for Windows 11 and Windows Server 2022/2025, while GreenPlasma is a privilege-escalation flaw that could yield a SYSTEM shell. The disclosures follow earlier leaks (BlueHammer, RedSun), with the researcher promising more PoCs; Microsoft says it is investigating and urging mitigations like BitLocker PINs and BIOS passwords, though some configurations (such as TPM-only) may remain vulnerable.

By TechLogHub
Microsoft fixes Windows Autopatch bug installing restricted drivers
May 13, 2026

Microsoft fixes Windows Autopatch bug installing restricted drivers

Microsoft fixed a Windows Autopatch bug in the EU that caused restricted driver updates to install on some Windows 11 devices (versions 23H2, 24H2, 25H2) despite IT policies, potentially causing reboots or failures. The fix is service-side and requires no action from customers. The article also notes a recent Windows Server 2019/2022 upgrade-to-2025 issue and new Office installation problems on Windows 365 after a service update.

By TechLogHub
Microsoft says some users can't install Office on Windows 365 devices
May 13, 2026

Microsoft says some users can't install Office on Windows 365 devices

Microsoft says a recent service update introduced a configuration change that blocks some Windows 365 users from downloading or installing Office. A fix is being developed and will be deployed with the next update, scheduled for Friday; in the meantime, affected users can manually download Office from the Microsoft 365 download page. The issue is tracked as WP1309017 and is classified as an advisory with no fixed remediation timeline yet.

By TechLogHub
US govt seeks Instructure testimony on massive Canvas cyberattack
May 13, 2026

US govt seeks Instructure testimony on massive Canvas cyberattack

US House Homeland Security Committee has asked Instructure to testify by May 21 about two ShinyHunters cyberattacks on the Canvas platform that exposed millions of student and staff records and disrupted final exams across multiple states; Instructure disclosed the breach on May 3 (intrusion detected April 29), with exposed data including names, emails and student IDs, while a second attack defaced login portals, and ShinyHunters later claimed extensive data theft and, after pressure, said the data was destroyed.

By TechLogHub
UK fines water supplier $1.3M for exposing data of 664k customers
May 12, 2026

UK fines water supplier $1.3M for exposing data of 664k customers

UK ICO fines South Staffordshire Water Plc £963,900 ($1.3M) for a 2020–2022 data breach that exposed the personal data of around 664,000 customers and staff, due to multiple security failures and a phishing-driven malware intrusion that went undetected for 20 months.

By TechLogHub
Instructure reaches 'agreement' with ShinyHunters to stop data leak
May 12, 2026

Instructure reaches 'agreement' with ShinyHunters to stop data leak

Instructure has announced an agreement with the ShinyHunters extortion group to stop the leakage of data stolen in a breach of the Canvas LMS, with the stolen data returned and destruction logs provided. The incident affected more than 30 million educators and students across 8,000 schools and universities, and ShinyHunters claimed about 3.6TB of data was stolen after exploiting Free-for-Teacher XSS flaws and even defaced Canvas login pages on May 7. Canvas has been restored, Free-for-Teacher accounts were temporarily shut, and Instructure will share further updates in a May 13 webinar; the FBI cautions that paying a ransom does not guarantee safety from further extortion.

By TechLogHub
Instructure confirms hackers used Canvas flaw to deface portals
May 11, 2026

Instructure confirms hackers used Canvas flaw to deface portals

Instructure confirmed that hackers exploited a Canvas vulnerability to deface login portals and leave an extortion message, using multiple XSS flaws to gain authenticated admin sessions. A second attack on May 7 leveraged the same flaw to pressure a ransom after an initial breach disclosed on April 29. The Free-for-Teacher environment was affected, Canvas was offline briefly and restored by May 9, and ShinyHunters claim to have stolen data from 8,809 institutions—up to 275 million records—though the defacement itself did not compromise data.

By TechLogHub
Webinar this week: Prevention alone is not enough against modern attacks
May 11, 2026

Webinar this week: Prevention alone is not enough against modern attacks

Bleeding-edge webinar (May 14, 2026 at 2:00 PM ET) from BleepingComputer explains why prevention alone isn’t enough against modern cyberattacks. Featuring Austin O’Saben of Kaseya, the session covers AI-driven phishing, SaaS abuse, and how trusted platforms are exploited, arguing that robust backups and a rapid recovery plan are essential to cyber resilience. Attendees will learn how to integrate prevention, detection, and quick recovery to minimize downtime and data loss.

By TechLogHub
Ivanti warns of new EPMM flaw exploited in zero-day attacks
May 7, 2026

Ivanti warns of new EPMM flaw exploited in zero-day attacks

Ivanti has issued a warning about a new high-severity remote code execution flaw in Endpoint Manager Mobile (EPMM), CVE-2026-6973, being exploited in zero-day attacks. The vulnerability affects EPMM versions up to 12.8.0.0 and requires admin authentication; users are urged to upgrade to 12.6.1.1, 12.7.0.1, or 12.8.0.1 and to rotate admin credentials. Ivanti says cloud products are unaffected and exploitation appears limited, though hundreds of EPMM IPs are exposed online per Shadowserver. The company also patched four additional high-severity EPMM flaws (CVE-2026-5786/7/8 and 7821) with no confirmed in-the-wild exploitation, while earlier CVEs (1281/1340) had been exploited in the wild.

By TechLogHub
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
May 7, 2026

The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls

New analysis reveals traditional DLP misses browser-based data flows, with 46% of sensitive file uploads to web apps ending up in unsanctioned accounts. As work shifts to browser apps and AI tools, data is copied, pasted, typed into forms, or uploaded from personal or shadow accounts, often evading endpoint and network DLP. A real-world example shows proprietary code moving from a private repository into a personal ChatGPT session, leaving the organization unprotected. Browser-native DLP, like Keep Aware, runs inside the browser to inspect data in real time, understand context, and enforce inline controls—complementing existing DLP. The piece invites readers to book a demo to see browser-native DLP in action.

By TechLogHub
Americans sentenced for running 'laptop farms' for North Korea
May 7, 2026

Americans sentenced for running 'laptop farms' for North Korea

Two U.S. nationals were sentenced to 18 months in prison for running “laptop farms” that helped North Korean IT workers fraudulently obtain remote jobs at nearly 70 American companies. Matthew Knoot operated the scheme from Nashville (July 2022–August 2023) using stolen identities, while Erick Prince aided North Korean workers through Taggcar Inc (2020–2024). The case, part of a broader effort to disrupt North Korea’s illicit IT revenue, involved substantial victim payments and remediation costs, with restitution and forfeiture orders issued.

By TechLogHub
Palo Alto Networks firewall zero-day exploited for nearly a month
May 7, 2026

Palo Alto Networks firewall zero-day exploited for nearly a month

Security researchers warn of a critical PAN-OS zero-day (CVE-2026-0300) in the User-ID Authentication Portal that has been exploited by suspected state-sponsored actors to achieve unauthenticated remote code execution on internet-facing PA-Series and VM-Series firewalls for nearly a month. Exploitation began around April 9, 2026; attackers succeeded about a week later and deployed EarthWorm and ReverseSocks5 to establish covert tunnels. Shadowserver reports thousands of exposed PAN-OS VM-series devices, with most in Asia and North America; Cloud NGFW and Panorama are unaffected. Patches are expected to begin rolling out on May 13; CISA has added CVE-2026-0300 to the KEV catalog and ordered Federal agencies to secure vulnerable devices by May 9. In the meantime, admins should restrict access to the Captive Portal or disable it and verify settings under Device > User Identification > Authentication Portal Settings.

By TechLogHub
Fake Claude AI website delivers new 'Beagle' Windows malware
May 7, 2026

Fake Claude AI website delivers new 'Beagle' Windows malware

Security researchers warn of a fake Claude AI website that distributes a trojanized Claude-Pro Relay installer, delivering a Windows backdoor named Beagle. The campaign uses a bogus Claude-Pro-windows-x64.zip that drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll, loading DonutLoader and Beagle in memory to grant attackers remote access, with C2 traffic to license.claude-pro.com on ports 443/8080. Mitigation advises downloading Claude only from the official portal and watching for NOVupdate artifacts; attribution remains unclear, though Sophos links Beagle to operators associated with PlugX.

By TechLogHub

Showing 20 of 423 articles