Trellix Breach: Probe Ongoing as Supply Chain Risks Mount for Cyber Vendors
Key Trellix source code breach updates:
- Incident Scope: Unauthorized access to portion of repo; no evidence of exploitation or release process...

Created by Elhanan Abrams
48‑hour breach, ransomware, zero‑day intel for critical infrastructure and government
Explore the latest content tracked by Cyber Threat Pulse
Key Trellix source code breach updates:
Akira group struck Maximum Mold in a ransomware attack discovered on 2026-05-05, highlighting latest victim trends in ongoing summaries.
Zero-day flaws in AI agents on major cloud platforms let attackers bypass access controls and escalate privileges, triggering a $25B security redesign. Critical infrastructure teams: audit AI integrations urgently for incident response.
Critical infrastructure hit: Hackers stole millions of confidential documents from Fujairah Port in UAE.
Urgent alert: Google confirms CVE-2026-0073, a critical Android vulnerability enabling zero-click remote code execution with no user interaction. Patch immediately to mitigate risks to enterprise and government devices.
Qilin ransomware group strikes Ahorramas, a Spanish retailer, in the latest attack on European enterprises. IR teams: prioritize Qilin monitoring for rapid response.
Expert take: Designating ransomware groups as terrorists draws a new red line, influencing adversary target selection and aiding incident...
Key developments in ShinyHunters' edtech attack:
Critical auth bypass exploited globally:
Insider glimpse into live ransomware extortion:
Critical threats in MOVEit Automation:
Key containment actions by IBM Italy's Sistemi Informativi: activated incident response, collaborated with specialists, restored services, and...
Key lesson from UCSF attack: Stolen VPN credentials let ransomware in, but segmentation confined it to one environment segment—sparing healthcare ops...
ShinyHunters threatens to leak 3.65TB+ of Canvas data, including PII for students/teachers and billions of private messages from 275M users across...
Escalating exploitation of cPanel's auth bypass zero-day (CVE-2026-41940) now drives mass 'Sorry' ransomware attacks, with 8,859 hosts showing...
China-linked Salt Typhoon suspected in late April breach of Sistemi Informativi, IBM Italy-owned IT provider for public agencies.
Key highlights:
-...