# Archive

Browse past daily curated stories

May 08 May 05 May 03 May 02 May 01 Apr 30 Apr 28 Apr 26 Apr 25 Apr 24 Apr 23 Apr 22 Apr 21 Apr 20 Apr 19 Apr 18 Apr 17 Apr 16 Apr 15 Apr 14 Apr 12 Apr 11 Apr 10 Apr 09 Apr 08 Apr 07 Apr 05 Apr 04 Apr 03 Apr 02

Thursday, April 30, 2026

  1. 1
    0
    Schneier on Security threat-intel
    Claude Mythos Has Found 271 Zero-Days in Firefox

    Claude Mythos has discovered 271 zero-day vulnerabilities in Firefox since February 2026, building on previous work with Opus 4.6 that found 22 security-sensitive bugs in Firefox 148. This represents an extraordinary scale of AI-assisted vulnerability discovery that demonstrates the potential for autonomous security research tools to uncover previously unknown flaws in critical software.

  2. 2
    0
    BleepingComputer general
    Official SAP npm packages compromised to steal credentials

    Multiple official SAP npm packages were compromised in a TeamPCP supply-chain attack using "Mini Shai-Hulud" credential-stealing malware that targets developers' authentication tokens. The campaign specifically targeted SAP's JavaScript and cloud application packages, representing a significant threat to enterprise development environments relying on SAP's ecosystem.

  3. 3
    0
    BleepingComputer general
    GitHub fixes RCE flaw that gave access to millions of private repos

    GitHub patched CVE-2026-3854, a critical remote code execution vulnerability allowing authenticated users to achieve RCE with a single 'git push' command and potentially access millions of private repositories. The command injection flaw was discovered using AI reverse-engineering tools and affects both GitHub.com and GitHub Enterprise Server.

  4. 4
    0
    BleepingComputer general
    cPanel, WHM emergency update fixes critical auth bypass bug

    cPanel released emergency updates for a critical authentication bypass vulnerability affecting all supported versions that allows unauthenticated access to control panel software. The issue is patched in versions 11.110.0.97, 11.118.0.63, 11.126.0.54, and 11.132.0.29, requiring immediate server updates.

  5. 5
    0
    BleepingComputer general
    CISA orders feds to patch Windows flaw exploited as zero-day

    CISA added CVE-2024-1708 (ConnectWise ScreenConnect path traversal) and an actively exploited Windows vulnerability to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch these zero-day flaws. Both vulnerabilities are being actively exploited in the wild according to CISA's threat intelligence.

  6. 6
    0
    BleepingComputer general
    Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

    CVE-2026-42208, a critical SQL injection vulnerability in BerriAI's LiteLLM large language model gateway, is being actively exploited within 36 hours of public disclosure. The CVSS 9.3 flaw allows attackers to read and modify database content in LiteLLM proxy deployments used for managing AI model access.

  7. 7
    0
    BleepingComputer general
    Popular WordPress redirect plugin hid dormant backdoor for years

    The Quick Page/Post Redirect WordPress plugin, installed on over 70,000 sites, contained a dormant backdoor added five years ago that enables arbitrary code injection. The long-term compromise demonstrates sophisticated supply chain persistence tactics targeting popular WordPress infrastructure.

  8. 8
    0
    BleepingComputer general
    Broken VECT 2.0 ransomware acts as a data wiper for large files

    VECT 2.0 ransomware contains a critical encryption flaw that permanently destroys files larger than 131KB instead of encrypting them due to improper nonce handling across Windows, Linux, and ESXi systems. The implementation error makes the malware function more like a wiper, with no possibility of data recovery even for attackers.

  9. 9
    0
    BleepingComputer general
    Hackers arrested for hijacking and selling 610,000 Roblox accounts

    Ukrainian police arrested three individuals who hijacked over 610,000 Roblox gaming accounts and sold them for $225,000 in profits. The operation targeted both Ukrainian and foreign players' accounts containing valuable digital items, rare equipment, and real-money purchased in-game currency.

  10. 10
    0
    Dark Reading general
    AI Finds 38 Security Flaws in Electronic Health Record Platform

    AI tools discovered 38 security vulnerabilities in OpenEMR's electronic health record platform used by more than 100,000 healthcare providers worldwide. The flaws enable database compromise, remote code execution, and theft of sensitive patient information, highlighting critical risks in widely-deployed medical software.