top of page

Weekly INK
Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

Issue #207 - July 13, 2026
2-Click Cursor Exploit Enables Dev Environment Takeover Source: Dark Reading Researchers found that Cursor AI could be abused through disguised links that install malicious MCP servers inside a developer environment. The attack chain relies on ordinary-looking clicks and limited warning visibility, creating a path to steal source code, secrets, or run commands with the developer’s privileges. Link to article GigaWiper Lets Threat Actors Choose Their Own Destructive Attack Sou

Weekly INK
Jul 132 min read
Â
Â
Issue #206 - July 6, 2026
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows Source: Dark Reading Researchers disclosed GitLost, a prompt-injection weakness in GitHub agentic workflows that could let unauthenticated attackers use a public GitHub issue to pull private repository data. The story highlights a fast-growing risk: AI agents with broad access can be manipulated by ordinary text if trust boundaries are weak. Link to article Fake IT support calls on Microsoft Teams push EtherRAT

Weekly INK
Jul 62 min read
Â
Â
Issue #205 - June 29, 2026
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Source: SecurityWeek Researchers linked the FortiBleed credential-harvesting campaign to INC and Lynx ransomware activity. SOCRadar reported scanning against thousands of FortiGate portals, hundreds of successful administrative compromises, and at least 12 ransomware deployments, showing how stolen edge-device credentials can quickly become enterprise-wide extortion access. Link to article China-Linked Group Targets S

Weekly INK
Jun 292 min read
Â
Â
Issue #204 - June 22, 2026
CISA warns of max severity Ubiquiti flaws exploited in attacks Source: BleepingComputer CISA warned that attackers are actively exploiting critical Ubiquiti UniFi OS flaws and Lantronix serial-to-ethernet server vulnerabilities. The directive gives federal agencies only three days to apply fixes or mitigations, underscoring how exposed edge and network management systems remain high-value targets for fast-moving exploitation. Link to article More Malicious OpenClaw Skills Thr

Weekly INK
Jun 222 min read
Â
Â
Issue #203 - June 15, 2026
INC Ransomware Thrives by Mastering the Basics Source: Dark Reading INC ransomware has grown by focusing on practical, repeatable intrusion methods rather than novel tooling. Researchers said the group targets high-pressure sectors, uses familiar techniques such as stolen credentials, phishing, and unpatched remote services, and benefits from affiliate scalability as other ransomware groups decline or reorganize. Link to article Fileless Phantom Stealer Targets Browser Creden

Weekly INK
Jun 152 min read
Â
Â
Issue #202 - June 08, 2026
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks Source: BleepingComputer Oracle PeopleSoft servers are being targeted in ongoing data theft attacks attributed to ShinyHunters, with the group claiming data from more than 100 organizations. The report is notable because PeopleSoft often supports HR, payroll, finance, procurement, and student administration, making exposed systems a high-value business data target. Link to article Critical HVAC and UPS Vulner

Weekly INK
Jun 82 min read
Â
Â
Issue #201 - June 01, 2026
Cyber Insurance Rates Are Dropping, but Exclusions Widen Source: Dark Reading Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix. The good news for enterprises is that cyber insurance policies are still affordable. The bad news is that coverage exclusions are increasing, and some might catch customers by surprise. Link to article VS Code zero-day lets hackers steal GitHub tokens in one click Sou

Weekly INK
Jun 12 min read
Â
Â
Issue #200 - May 25, 2026
KnowledgeDeliver flaw exploited as a zero-day to install web shells Source: BleepingComputer Attackers exploited CVE-2026-5426, a deserialization flaw in the KnowledgeDeliver LMS, to gain unauthenticated remote code execution and deploy the Godzilla web shell. Mandiant said the issue stemmed from shared hardcoded ASP.NET machine keys, enabling malicious ViewState payloads and follow-on delivery of a Cobalt Strike backdoor. Link to article Feeding Frenzy: 'Megalodon' Malware I

Weekly INK
May 282 min read
Â
Â
Issue #199 - May 18, 2026
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email Source: The Hacker News Microsoft disclosed active exploitation of CVE-2026-42897, a spoofing flaw rooted in cross-site scripting on on-premises Exchange. The issue can let attackers deliver crafted emails that execute JavaScript in Outlook Web Access sessions. CISA has already added the bug to its known exploited vulnerabilities catalog, underscoring the urgency for defenders. Link to article Critic

Weekly INK
May 182 min read
Â
Â
Help us Prevent Breaches.
Subscribe to our Weekly INK newsletter. We will never share your information.
bottom of page

