Ethical Hacking Mission Control
This live lab is a safe space for defenders, red teamers, and curious hackers to sharpen their tradecraft using real tooling and real telemetry. Every article, lab module, and intel briefing is curated to help you practice responsible disclosure, grow your skill set, and support the security community.
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
Trellix Confirms Source Code Breach With Unauthorized Repository Access
30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
Top Five Sales Challenges Costing MSPs Cybersecurity Revenue
Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About
After Mythos: New Playbooks For a Zero-Window Era
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
Toxic Combinations: When Cross-App Permissions Stack into Risk
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time
Why Most AI Deployments Stall After the Demo
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Bug Bounty Radar
Hand-picked programs with live scope and standout rewards to help you focus your next responsible disclosure run.
FastAPI Cloud
HackerOne • Updated 2024-05-18
Prototype pollution in async workers and GraphQL stitching flaws.
Scope: api.fastapicloud.com, *.fastapicloud.com
Program brief →Supply Chain Monitor
Bugcrowd • Updated 2024-05-22
Dependency confusion, pipeline breakout, and artifact poisoning.
Scope: *.scm.dev, api.scm.dev
Program brief →Secure Notes
Intigriti • Updated 2024-05-17
OAuth misconfigurations, storage isolation, and advanced XSS chains.
Scope: app.securenotes.io, api.securenotes.io
Program brief →OpenTelemetry Hub
YesWeHack • Updated 2024-05-20
Collector escapes, tenant isolation bugs, and SSRF via exporters.
Scope: *.otelhub.dev
Program brief →