PROBABLYPWNED

Cybersecurity News & Threat Intelligence

View all →
Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

James RiveraMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

James RiveraMay 23, 2026
Apache HTTP/2 Double-Free Enables DoS and RCE
Vulnerabilities4 min read

Apache HTTP/2 Double-Free Enables DoS and RCE

CVE-2026-23918 in Apache HTTP Server 2.4.66 lets attackers crash workers trivially or achieve remote code execution through a double-free in mod_http2. Upgrade to 2.4.67 immediately.

Marcus ChenMay 23, 2026
Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS
Vulnerabilities4 min read

Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS

Ubiquiti releases emergency patches for three maximum-severity vulnerabilities in UniFi OS that allow unauthenticated remote attackers to take full control of network appliances. 100,000 devices exposed.

Marcus ChenMay 23, 2026
KimWolf Botnet Operator Arrested After 30 Tbps DDoS Attacks
Announcements3 min read

KimWolf Botnet Operator Arrested After 30 Tbps DDoS Attacks

Canadian authorities arrest 23-year-old Jacob Butler for operating the KimWolf IoT botnet. The DDoS-for-hire operation enslaved nearly 2 million devices and set volumetric attack records.

ProbablyPwned TeamMay 22, 2026

Security Guides

Learn about ransomware, phishing, malware, and essential online safety practices.

Recommended Resources

Curated books, tools, and resources to deepen your cybersecurity knowledge.

Stay Informed

Get the latest cybersecurity news delivered to your inbox.

We respect your privacy. Unsubscribe anytime.