This week's cybersecurity landscape is dominated by the active exploitation of critical zero-day vulnerabilities in Microsoft products, including two in Defender and a new unpatched flaw in Windows dubbed 'MiniPlasma'. Concurrently, multiple sophisticated supply chain attacks have compromised hundreds of open-source packages across npm, PyPI, and Packagist, deploying credential-stealing worms and malware. New ransomware strains like 'Aur0ra' are emerging with dual-extortion tactics, while Iran-linked APTs escalate espionage campaigns, highlighting a period of heightened risk across software supply chains, endpoint security, and critical infrastructure.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.