General Medium 6 May

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. "These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging t Source: The Hacker News

General Medium 6 May

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been des Source: The Hacker News

General Medium 5 May

Hacker Conversations: Joey Melo on Hacking AI

AI red team specialist details his methods for manipulating AI guardrails through jailbreaking and data poisoning, helping developers harden machine learning models. The post Hacker Conversations: Joey Melo on Hacking AI appeared first on SecurityWeek. Source: Security Week

General Medium 5 May

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary Source: The Hacker News

General High 5 May

pnpm 11 Enhances npm Supply Chain Security by Default

pnpm 11 introduces a new default security feature to combat supply chain attacks in the npm ecosystem. This update enables a minimum release age for packages, directly addressing the risk of malicious code injection into developer environments. The move aims to enhance security protections and reduce the overall attack surface for software development. Source: Cybersecurity […]

Why it matters: Indian organizations relying on npm for software development should ensure their teams are aware of and leverage such security enhancements to mitigate supply chain risks.