logo

ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories

ID: a480328a-d826-5eba-8e3f-5665401cb683

STIX ID: report--a480328a-d826-5eba-8e3f-5665401cb683

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

This weekly ThreatsDay bulletin highlights a broad set of active threats and security developments: a new credential stealer (MicroStealer) and multiple infostealer campaigns (Vidar, NWHStealer, NuGet typosquats); critical vulnerabilities in industrial (Eclipse BaSyx CVE-2026-7411/7412) and enterprise software (MOVEit Automation CVE-2026-4670, Salesforce fixes); flawed VECT 2.0 ransomware causing irrecoverable data loss; large-scale smishing and malvertising campaigns; supply-chain hardening efforts (pnpm, NuGet) and vendor responses (Oracle monthly CSPUs, Proton PQC); plus systemic risks such as Edge keeping plaintext passwords in memory and AI tools accelerating exploit discovery—collectively indicating active exploitation, widespread impact across sectors, and an elevated operational tempo for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.