04/27

PyPI package with 1.1M monthly downloads hacked to push infostealer

https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/
PyPI package with 1.1M monthly downloads hacked to push infostealer

Critical bug in CrowdStrike LogScale let attackers access files

https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html
Critical bug in CrowdStrike LogScale let attackers access files

Nan Wang (sakura) & Ziling Chen (R1nd0) | OffensiveCon

https://www.offensivecon.org/speakers/2026/nan-wang-and-ziling-chen.html
Nan Wang (sakura) & Ziling Chen (R1nd0) | OffensiveCon

Google Online Security Blog: AI threats in the wild: The current state of prompt injections on the web

https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html
Google Online Security Blog: AI threats in the wild: The current state of prompt injections on the web

Microsoft updates the Windows Update Experience • The Register

https://go.theregister.com/feed/www.theregister.com/2026/04/27/microsoft_updates_the_windows_update/
Microsoft updates the Windows Update Experience • The Register

Windows Privilege Escalation 01: Initial Enumeration

https://niklas-heringer.com/penetration-testing/windows-privilege-escalation-01/
Windows Privilege Escalation 01: Initial Enumeration

Cybersecurity professional getting more work and less pay • The Register

https://go.theregister.com/feed/www.theregister.com/2026/04/27/from_a_massive_skills_gap/
Cybersecurity professional getting more work and less pay • The Register

Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges

https://cybersecuritynews.com/nessus-agent-vulnerability-on-windows/
Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges

NDSS 2026 - FUZZING 2026, Keynote 2 by Sergej Dechand - YouTube

https://www.youtube.com/watch?v=yp-AKW36ihQ
NDSS 2026 - FUZZING 2026, Keynote 2 by Sergej Dechand - YouTube

Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops | Starstrike

https://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/
Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops | Starstrike

Microsoft says Outlook.com outage is causing sign‑in failures

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-outlookcom-outage-is-causing-sign-in-failures/
Microsoft says Outlook.com outage is causing sign‑in failures

Just a moment...

https://thehackernews.com/2026/04/checkmarx-confirms-github-repository.html
Just a moment...

Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records

https://cybersecuritynews.com/udemy-data-breach/
Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records