Microsoft confirmed on May 14 that CVE-2026-42897 — a cross-site scripting flaw in the Outlook Web Access component of Exchange Server 2016, 2019, and Subscription Edition — is under active ...
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...