This period saw a massive supply chain attack named 'Megalodon' compromise over 5,500 GitHub projects, while a critical Drupal SQL injection flaw (CVE-2026-9082) came under immediate mass exploitation. Other major events include the Lazarus Group deploying a new memory-only RAT, a data breach at legal tech firm DocketWise affecting 143,000, and the takedown of the 'First VPN' service used by cybercriminals, highlighting ongoing threats across the software supply chain, web applications, and organized cybercrime infrastructure.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.