General Medium 5 May

Hacker Conversations: Joey Melo on Hacking AI

AI red team specialist details his methods for manipulating AI guardrails through jailbreaking and data poisoning, helping developers harden machine learning models. The post Hacker Conversations: Joey Melo on Hacking AI appeared first on SecurityWeek. Source: Security Week

General Medium 5 May

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary Source: The Hacker News

General High 5 May

pnpm 11 Enhances npm Supply Chain Security by Default

pnpm 11 introduces a new default security feature to combat supply chain attacks in the npm ecosystem. This update enables a minimum release age for packages, directly addressing the risk of malicious code injection into developer environments. The move aims to enhance security protections and reduce the overall attack surface for software development. Source: Cybersecurity […]

Why it matters: Indian organizations relying on npm for software development should ensure their teams are aware of and leverage such security enhancements to mitigate supply chain risks.
General High 5 May

Microsoft Edge Stores Passwords in Cleartext Memory at Launch

A security researcher has uncovered a critical vulnerability in Microsoft Edge, revealing that the browser decrypts and stores all saved passwords in cleartext process memory upon launch. This exposure occurs regardless of user activity, making credentials susceptible to memory scraping attacks. The flaw, disclosed by PaloAltoNtwks Norway, highlights a significant risk to user data. Source: […]

Why it matters: Indian organizations using Microsoft Edge should be aware of this vulnerability and consider advising users on alternative password management or browser usage until a patch is released.
General High 5 May

Amazon SES Abuse for Phishing Bypasses Security Filters

Amazon's Simple Email Service (SES) is being exploited by threat actors to launch sophisticated phishing campaigns. These malicious emails are designed to bypass standard security filters and render traditional reputation-based blocking mechanisms ineffective. The technique allows attackers to deliver highly convincing phishing messages directly to inboxes, increasing the risk of compromise. Source: BleepingComputer

Why it matters: Indian organizations must enhance their email security defenses and user awareness training to counter phishing attacks leveraging Amazon SES, as these can bypass common security measures.
General High 5 May

CERT-In warns of rising AI-driven cyber threats, ‘Mythos’ concerns

India's CERT-In has issued a warning regarding the increasing prevalence of AI-driven cyber threats. The advisory specifically highlights concerns related to a potential threat named 'Mythos'. This alert underscores the evolving landscape of cyber risks powered by artificial intelligence. Source: Cityairnews

Why it matters: Indian organizations must enhance their cybersecurity defenses and threat intelligence capabilities to counter sophisticated AI-driven attacks warned by CERT-In.
General Low 5 May

IES Briefing: Trellix Discloses Data Breach After Source Code Repository Hack

Your browser does not support audio playback. About this briefing: AI-generated from the original story. Voices: Neerja & Prabhat. ▶ Read transcript Neerja: Cybersecurity firm Trellix has announced a data breach. Attackers gained unauthorized access to a part of its source code repository. This incident involved their internal development environment. Prabhat: This breach highlights significant […]

Telecom High 5 May

New MicroStealer Malware Targets Telecom, Education Sectors Globally

A new infostealer malware, MicroStealer, has emerged and is rapidly spreading across the threat landscape. First detected in December 2025, this malware quickly gained traction in sandbox environments. It is actively targeting organizations in the telecom and education sectors. Source: Cybersecurity News

Why it matters: Indian critical infrastructure operators, especially in the telecom sector, must update their threat intelligence and enhance detection mechanisms against this new infostealer.