TechLogHub Blog — Page 7 of 22
Insights, guides, and product strategy for builders and product teams.

VS Code zero-day lets hackers steal GitHub tokens in one click
Security researchers disclosed a Visual Studio Code zero-day that lets attackers steal GitHub OAuth tokens with a single click by abusing github.dev. A proof-of-concept shows an attacker installing a malicious extension via VS Code’s webview to capture the token and grant full access to all repositories the victim can access. There is no patch or CVE yet; users should mitigate by clearing cookies and on-device data for github.dev and watching for extension sign-in prompts, while the disclosure was made publicly after concerns with Microsoft’s security response process.

Over 116,000 Minecraft Systems Infected in WeedHack Malware Campaign
A large-scale WeedHack malware campaign has infected over 116,000 Minecraft systems since January, spreading through malicious mods, clients, and utilities promoted on YouTube and via SEO poisoning. WeedHack operates as a malware-as-a-service, offering a dashboard to view stolen data and a payload builder, with a free tier that steals session IDs, cookies, and passwords across multiple apps and browsers, plus paid tiers adding remote access, keylogging, webcam access, and file management. The campaign relies on more than 240 distribution URLs and 3,820 unique malicious JAR files, with victims mainly in the United States, Germany, India, and the UK. Many clients appear to be teenagers or young adults who use WeedHack’s tools to harass others. The article urges Minecraft players to download mods only from official sources and to consider the Minecraft Marketplace for safer alternatives.

AI-built ransomware toolkit automates EDR evasion, AD discovery
An AI-built ransomware toolkit automates Active Directory discovery and evasion of endpoint detection and response (EDR) tools, accelerating cybercrime. The framework employs multiple AI agents to develop, test, and refine modular Windows payloads with encryption and evasion techniques, using components like Cobalt Strike profiles, a Telegram-based C2, a Python payload loader, and a Cloudflare front-end. Sophos says the tool has been tested against EDRs from Sophos, CrowdStrike, and Microsoft, and notes the workflow is human-driven despite AI involvement. While it may resemble a red-team framework, researchers confirm it is used for criminal ransomware activity, with AI speeding up development rather than operating autonomously in victims’ environments.

Microsoft Exchange Online outage causes email delays, failures
Microsoft is investigating a widespread Exchange Online outage impacting mail flow in North America and Germany, causing significant email delays and delivery failures. The incident (EX1331830) was first acknowledged at 10:33 ET as engineers review reports to determine the root cause and next steps, with some messages remaining undelivered for over an hour. This disruption affects users’ ability to send and receive email.

CISA flags two-year-old Oracle flaw as actively exploited in attacks
CISA has classified the two-year-old Oracle WebLogic Server flaw CVE-2024-21182 as actively exploited and added it to the Known Exploited Vulnerabilities catalog. Federal agencies were ordered to patch WebLogic servers by June 4, 2026, under BOD 22-01, with a strong urging for private-sector defenders to patch promptly. The flaw affects WebLogic versions 12.2.1.4.0 and 14.1.1.0.0 and can be exploited remotely by unauthenticated attackers, potentially giving access to sensitive data or full server control. With about 1,592 exposed online according to Shodan, the guidance emphasizes applying vendor mitigations or discontinuing the product if mitigations are unavailable.

Google fixes one actively exploited Android zero-day, 124 flaws
Google’s June 2026 Android security patches fix 124 vulnerabilities, including an actively exploited zero-day (CVE-2025-48595) that can enable remote code execution and privilege escalation on Android 14+. The updates also address 18 critical flaws across System, Framework, and Qualcomm components and are released in two patch levels (2026-06-01 and 2026-06-05). Pixel devices will receive the updates first, with other OEMs likely to take longer. The patching continues a trend of prior zero-days such as CVE-2025-48633, CVE-2025-48572, and CVE-2026-21385 being addressed in earlier updates.

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Researchers link the DriveSurge group to massive campaigns that hijack thousands of sites to deliver malware via ClickFix and FakeUpdates. Using the open-source Traffic Distribution System zTDS, they tailor lures to visitors and redirect them to malicious payloads, including fake browser updates and PowerShell-based commands. The operation, which also targets macOS, acts as an initial access broker (PPI) and relies on dozens of malicious injection domains and fingerprints. Users are advised to download updates only from official app settings and to ignore unfamiliar update prompts.

WordPress malware campaign hides payloads in Steam profiles
GoDaddy researchers warn of a WordPress malware campaign that has infected nearly 2,000 sites since mid-2025 by embedding payloads in Steam Community profile comments. The attacker uses invisible Unicode characters to encode a payload that constructs a URL to a malicious JavaScript script, hiding the C2 channel on Steam to blend with legitimate traffic. The final stage delivers a backdoor that accepts base64-encoded PHP code via POST when a specific authentication cookie is present. Potential infection vectors include stolen admin credentials, compromised FTP/SFTP, vulnerable plugins/themes, or supply-chain compromises. Defense guidance includes watching for Steam URLs, suspicious JavaScript injections, outbound connections to Steam, and indicators like invisible characters or unusual cached entries; responders should restore from a known-good backup or perform thorough manual cleanup to prevent reinfection.

Microsoft confirms outage affecting MFA, My Sign-Ins platform
Microsoft confirmed an ongoing outage affecting users trying to set up Multi-Factor Authentication and access mysignins.microsoft.com, with reports of 504 Gateway Timeout errors. The company has switched to alternate infrastructure to mitigate the impact, is monitoring service health, and is exploring further mitigation options; the affected regions have not been specified, and the incident began around 5:00 AM ET.

Microsoft fixes KB5089549 Windows security update install issues
Microsoft has resolved the Windows 11 May 2026 security update install failures (KB5089549) caused by insufficient free space on the EFI System Partition, which produced 0x800f0922 errors and rollback messages. The fix is included in the KB5089573 preview cumulative update and will be delivered to all users with the June Patch Tuesday updates; users should install the latest update to avoid workarounds. For those who cannot install the May 26, 2026 updates yet, Known Issue Rollback provides a mitigation, and IT admins can deploy rollback via Group Policy.

WP Maps Pro bug exploited to create admin accounts on WordPress sites
Security researchers have uncovered a critical flaw in WP Maps Pro (CVE-2026-8732) affecting version 6.1.0 and earlier that allows unauthenticated attackers to create rogue administrator accounts by abusing a “temporary access” feature and generating passwordless login URLs. Discovered by David Brown, the vulnerability has driven thousands of exploit attempts. Wordfence reports ongoing abuse and the vendor released a patch (WP Maps Pro 6.1.1) on May 20, 2026; site administrators should update immediately and audit for unauthorized admin accounts.

Best Open Source Projects on GitHub in 2026: The Ones Worth Watching
GitHub now hosts over 4.3 million AI-related repositories. We cut through the noise to highlight the open source projects actually worth your attention in 2026 — from local AI assistants and LLM frameworks to runtime contenders and monitoring stacks.

Vibe Coding in 2026: How Indie Founders Are Shipping SaaS Without Writing Code
Vibe coding has gone from a Twitter meme to a mainstream movement. In 2026, non-technical founders are shipping real, revenue-generating SaaS products in days. Here's what's real, what tools to use, and what to watch out for.

Best Developer Tools in 2026: The Complete Guide for Builders
A curated breakdown of the best developer tools in 2026 — from AI coding assistants and deployment platforms to open-source picks — chosen for builders, indie founders, and dev teams who want to ship faster.

PAN-OS GlobalProtect VPN authentication bypass flaw (CVE-2026-0257) now exploited in attacks
Palo Alto Networks warns that CVE-2026-0257, a GlobalProtect authentication bypass in PAN-OS, is being actively exploited against unpatched devices. Rapid7 observed exploit activity starting May 17, 2026, with initial attacks from Vultr and Dromatics Systems, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on May 29, 2026 (mitigation required by June 1 for federal agencies). The flaw arises from how PAN-OS validates authentication override cookies, enabling forged cookies to bypass authentication; apply the latest patches or disable authentication override cookies / use separate certificates to mitigate.

New CIFSwitch Linux flaw gives root on multiple distributions
Researchers have disclosed CIFSwitch, a Linux local privilege-escalation in the CIFS subsystem that lets an unprivileged user forge cifs.spnego key requests to trigger root via cifs.upcall and a subsequent NSS lookup. It affects multiple distributions with vulnerable kernel+CIFS+cifs-utils combinations (notably Linux Mint 21.3/22.3, CentOS Stream 9, Rocky/AlmaLinux 9, Kali 2021.4–2026.1, and SLES 15 SP7), while some newer releases with stricter SELinux/AppArmor protections are shielded. A kernel patch (upstream commit 3da1fdf4…) now validates cifs.spnego request origins; mitigations include disabling the CIFS module, removing cifs-utils, and disabling unprivileged user namespaces, with a PoC exploit available for testing.

Google Chrome Adds Session Cookie Theft Protection for All Users
Google Chrome has made Device Bound Session Credentials (DBSC) generally available, binding session cookies to a user’s device using hardware roots like TPM or Secure Enclave to prevent stolen cookies from hijacking accounts or bypassing MFA. Rolled out to all Google Workspace and personal accounts, with DBSC enabled by default for Workspace and not disableable by admins. Debuted in 2024 and in beta since April 2026, DBSC shifts defense from detection to proactive prevention, reducing cookie-exfiltration risk even if the device is infected.

North Carolina Man Sentenced to More Than 10 Years for Selling Personal Data of 7 Million Elderly Americans to Jamaican Scammers
North Carolina man Troy Murray, also known as Steve Dixon, was sentenced to 121 months in federal prison for selling the personal data of more than 7 million elderly Americans to Jamaican scammers, a scheme that ran from 2016 to 2023, earned him over $5.2 million, and caused more than $9.5 million in losses; he sold lead lists with names, addresses, phone numbers and emails for about $500 per 100–300 names and later accepted prepaid gift cards, with his son facing money-laundering charges related to the proceeds as elder fraud continues to rise nationwide per the FBI’s 2025 IC3 report.

US charges Google security engineer with Polymarket insider trading
Google security engineer Michele Spagnuolo has been charged with insider trading after allegedly using confidential Google data to place bets on Polymarket, earning about $1.2 million. Prosecutors say he accessed Google's "Year in Search" data labeled "Google Confidential" and, under the alias "AlphaRaccoon" on Polymarket, placed bets on roughly 25 unlikely outcomes with near-perfect accuracy from October 2025 through December 2025. The FBI traced the proceeds to a payment processor account registered in Spagnuolo's name, while the CFTC filed a parallel civil action seeking restitution, disgorgement, penalties, and trading/registration bans. Spagnuolo faces up to 10 years in prison for commodities fraud and 20 years for each counts of wire fraud and money laundering, in addition to potential penalties. The case underscores that corporate insiders cannot misuse confidential information for personal financial gain.

Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers exploited FortiClient EMS CVE-2026-35616 to deliver EKZ, an undocumented infostealer, by disguising the payload as a Fortinet endpoint update and executing it through FortiClient VPN scripting workflows. The attack uses an authentication bypass to run commands, download EKZ, and exfiltrate credentials, browser data, and other sensitive information to an attacker-controlled server after tampering with EMS configurations and VPN policies. Fortinet released emergency hotfixes for versions 7.4.5 and 7.4.6; CISA ordered federal agencies to patch, and Arctic Wolf notes ongoing campaigns with many exposed EMS instances, offering detection guidance on certificate-auth anomalies and unusual remote-access changes.
Showing 20 of 423 articles


