Category: cyber-security-news
-
Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets
Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets Wireshark, the world’s most widely used open-source network protocol analyzer, has released a major security update addressing over 40 vulnerabilities, several of which enable arbitrary code execution through malformed packet injection or malicious capture files. Organizations and individuals relying on Wireshark for network monitoring,…
-
Anthropic Launches Claude Security in Public Beta for Enterprise Customers
Anthropic Launches Claude Security in Public Beta for Enterprise Customers Anthropic has opened Claude Security to public beta for Claude Enterprise customers, bringing AI-powered vulnerability detection directly into production codebases without the need for custom tooling or API integrations. Claude Security leverages the Opus 4.7 model to perform end-to-end security analysis across your codebase. The…
-
Microsoft Windows 11 April 2026 Security Update Breaks Third-Party Backup Applications
Microsoft Windows 11 April 2026 Security Update Breaks Third-Party Backup Applications Microsoft’s April 2026 cumulative security update for Windows 11 is causing significant disruptions for users relying on third-party backup software, triggering an MS-DEFCON level 3 advisory from security patch analyst Susan Bradley at AskWoody. The problematic update, KB5083769, applies to Windows 11 versions 24H2…
-
OpenAI Releases 5-Point Action Plan to Strengthen AI-Powered Cyber Defense
OpenAI Releases 5-Point Action Plan to Strengthen AI-Powered Cyber Defense OpenAI has published a comprehensive cybersecurity action plan titled “Cybersecurity in the Intelligence Age: An Action Plan for Democratizing AI-Powered Cyber Defense,” outlining a five-pillar strategy to equip trusted defenders with advanced AI capabilities while preventing adversarial misuse. Artificial intelligence is fundamentally reshaping the cybersecurity…
-
CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs
CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs A new open-source project called CVE MCP Server is redefining how security teams triage vulnerabilities, transforming Anthropic’s Claude AI into a fully capable security analyst by giving it direct, correlated access to 27 intelligence tools spanning 21 external…
-
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent A new threat has quietly taken root in the software development world, using an AI coding assistant as an unknowing participant in a supply chain attack. A malicious npm package campaign called PromptMink surfaced after being introduced into an open-source autonomous crypto trading project through a…
-
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild In early 2026, two critical authentication bypass vulnerabilities in the popular open-source Qinglong task scheduler were actively exploited by hackers. According to Snyk security reports, unauthenticated attackers breached publicly accessible panels, achieving remote code execution to install a hidden, resource-draining cryptominer named .fullgc. Qinglong is a self-hosted…
-
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution A newly identified remote access trojan called KarstoRAT has been found in sandbox analyses and malware repositories since early 2026. The malware gives attackers a broad set of remote-control capabilities over compromised Windows machines, including webcam capture, audio recording, keylogging, screenshot theft, and…
-
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. The group first appeared in December 2025 and rapidly scaled its activity through February 2026,…
-
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files and demands payment for decryption, VECT 2.0 permanently destroys any file…
-
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group behind this activity is BlueNoroff, a financially motivated subgroup known for stealing digital assets. This…
-
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) ecosystem. System administrators and web hosting providers are…
-
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a…
-
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the matching Docker images on the GitHub…
-
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots Whenever someone uses Windows Remote Desktop, the operating system quietly saves visual fragments of the active session. As recently highlighted by SCYTHE Labs, attackers can easily extract these breadcrumbs and rebuild them into readable screenshots. This process requires no special privileges, takes just…
-
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override Cybersecurity researchers have recently disclosed three moderate-severity vulnerabilities in OpenClaw, an AI agent framework previously known as Clawdbot and Moltbot. Distributed as an npm package, these security flaws allow bypasses of policy enforcement, gateway configuration mutations, and host override attacks that could lead to credential exposure.…
-
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes Researchers from the Czech Technical University in Prague have developed a new adversarial malware generator targeting Linux ELF binaries. It achieves a 67.74% evasion rate against ML-based malware detectors while keeping the payload fully functional. Published on arXiv on April 24, 2026, the study by…
-
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography A well-known Iranian state-sponsored hacking group called OilRig, also tracked as APT34 and Helix Kitten, has been found hiding its command-and-control (C2) server configuration inside a regular-looking image file stored on Google Drive. The threat group used a technique called LSB (Least Significant Bit)…
-
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage payloads inside JPEG image files and TXT documents, making it much harder for security tools…
-
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities Multiple vulnerabilities in the CODESYS Control runtime, one of the world’s most widely adopted software-based programmable logic controller (Soft PLC) platforms. According to Nozomi Networks Labs researchers, by chaining these security flaws, an authenticated attacker can replace a legitimate industrial control application with a backdoored version, thereby…
-
Top 10 Best NDR (Network Detection and Response) Solutions in 2026
Top 10 Best NDR (Network Detection and Response) Solutions in 2026 In the modern enterprise, the network is the ultimate source of ground truth. As organizations accelerate their digital transformation and adopt complex, cloud-native security architectures, the traditional perimeter has dissolved. Threat actors routinely bypass endpoint defenses using compromised credentials, living-off-the-land (LotL) binaries, and highly…
-
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets The fast16 malware is a recently exposed sabotage‑capable threat designed to target extremely high‑value environments and ultra‑expensive systems with precision. It does not behave like common commodity malware that aims for broad infections, but instead focuses on select victims where disruption or long‑term control can cause…
-
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing A new open-source toolkit called pentest-ai-agents is redefining how security professionals leverage AI in penetration testing workflows, transforming Anthropic’s Claude Code into a fully specialized offensive security research assistant powered by 28 domain-specific subagents. Released by security researcher 0xSteph on GitHub, pentest-ai-agents is a collection of…
-
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to software developers. This activity follows a…
-
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued a full patch. Security researchers confirmed the flaw allowed threat actors to inject an invalid MWEB (MimbleWimble…
-
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented by Kaspersky application security specialist Haidar Kabibo at Black Hat Asia 2026 on…
-
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly valued targets for cybercriminals because they provide direct pathways into corporate networks. When compromised, these platforms allow threat actors…
-
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI representations are created equal. In December 2025, Anthropic transformed its San Francisco office into a live classified marketplace,…
-
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across…
-
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum — “Pay or Leak.” ADT, headquartered in Boca Raton, Florida, disclosed the incident via a Form 8-K…
-
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access State-sponsored threat actors are actively targeting Cisco Firepower devices by chaining known vulnerabilities to deploy a highly customized backdoor. Cisco Talos recently discovered that the espionage-focused threat group UAT-4356 is exploiting two n-day vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, to infiltrate Firepower Extensible…
-
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of several Chromium-based browsers. This undocumented behavior occurs without user consent, raising significant privacy and security concerns…
-
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weaponize this process. Hackers are now building fake CAPTCHA pages that trick users into…
-
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing web applications at a massive…
-
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data Ransomware attackers are no longer relying only on widely known tools to steal data. Affiliates linked to the Trigona ransomware group have taken a more calculated approach by building their own custom data exfiltration tool, one that gives them greater precision, speed, and control over…
-
Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide
Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide A major investigation has revealed that sophisticated threat actors are exploiting fundamental vulnerabilities in global mobile networks to track users worldwide. By abusing legacy 3G SS7 and 4G Diameter signaling protocols, hackers are successfully bypassing telecom firewalls to conduct silent, cross-border espionage. The extensive…
-
Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update
Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update Microsoft is actively investigating a known issue preventing some users from joining Microsoft Teams meetings on Windows devices, following a recent update to the Microsoft Edge browser. The disruption is affecting organizations, including those using NHSmail infrastructure, with reports indicating that scheduled meetings…
-
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation, a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software vulnerability. Google Threat…
-
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux distributions in their default installations. The flaw allows any local unprivileged user to silently install or remove system packages,…
-
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages Apple released iOS 26.4.2 and iPadOS 26.4.2 on April 22, 2026, to patch a critical notification privacy vulnerability that allowed law enforcement to extract Signal message content from iPhones — even after the app had been deleted. The flaw, tracked as CVE-2026-28950,…
-
Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code
Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code A significant supply chain attack targeting the official checkmarx/kics Docker Hub repository, where threat actors pushed trojanized images capable of harvesting and exfiltrating sensitive developer credentials and infrastructure secrets. Docker’s internal monitoring flagged suspicious activity around KICS image tags on April 22, 2026, and promptly…
-
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware A large-scale malware distribution campaign has been uncovered involving 109 fake GitHub repositories that were used to trick users into downloading two dangerous malware tools named SmartLoader and StealC. The campaign was carefully built around cloned versions of legitimate open-source projects, making it hard…
-
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft Cybercriminals are now using Google’s own advertising platform to steal cryptocurrency from unsuspecting users. They place fake ads that look exactly like real links to popular crypto applications, and when users click on them, they land on websites designed to drain their…
-
Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks
Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to apply patches immediately.…
-
1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online
1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online A critical spoofing vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, remains unpatched on over 1,370 internet-facing IP addresses worldwide, according to fresh scanning data from the Shadowserver Foundation, even as the flaw sits on CISA’s Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation…
-
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability resides in a…
-
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor through a technique known as…
-
Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability
Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the Microsoft.AspNetCore.DataProtection NuGet package. The out-of-band release was prompted after customers began reporting decryption failures…
-
Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments
Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to hijack AI coding agents and steal API keys and access tokens directly from CI/CD…
-
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixel-perfect clone of the Zimbra email login portal to steal employee credentials. The…
-
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes by luring them to a malicious webpage. Tracked as CVE-2026-33829, the flaw resides in how Windows Snipping…
-
iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution
iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution Cybersecurity researchers, working in partnership with OpenAI, have uncovered a fascinating and severe vulnerability in iTerm2, a widely used macOS terminal emulator. According to Califio, the flaw abuses the application’s SSH integration feature, allowing attackers to turn seemingly harmless text output into…
-
British National Admits Hacking Companies and Stealing Millions in Virtual Currency
British National Admits Hacking Companies and Stealing Millions in Virtual Currency A British man has pleaded guilty in the United States to his role in a large cybercrime scheme that used SMS phishing, company network intrusions, and SIM swapping to steal at least $1 million in virtual currency from victims across the country. Tyler Robert…
-
Public Notion Pages Leaks Profile Photos and Email address of Editors
Public Notion Pages Leaks Profile Photos and Email address of Editors Notion, a popular productivity and collaboration platform, is under significant scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak includes full names, email…
-
NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020
NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020 The National Institute of Standards and Technology (NIST) has officially updated how it processes vulnerabilities in the National Vulnerability Database (NVD). According to an April 15, 2026 announcement, NIST is abandoning its comprehensive analysis approach in favor of a targeted, risk-based model.…
-
Google Uses Gemini AI to Stop Malicious Ads From Threat Actors – 8.3 billion ads Blocked
Google Uses Gemini AI to Stop Malicious Ads From Threat Actors – 8.3 billion ads Blocked Threat actors are increasingly leveraging generative AI to launch sophisticated advertising scams at an unprecedented scale. In response, Google has integrated its advanced Gemini AI models into its security infrastructure to neutralize these threats actively. According to Google’s newly…
-
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch large-scale distributed denial-of-service attacks. The vulnerability at the center of this campaign,…
-
Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters
Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters A critical vulnerability in Flowise and multiple AI frameworks has been discovered by OX Security, exposing millions of users to remote code execution (RCE). The flaw stems from the Model Context Protocol (MCP), a widely used communication standard for AI agents developed by Anthropic.…
-
Microsoft Teams Right-Click Paste Broken Following Edge Browser Update
Microsoft Teams Right-Click Paste Broken Following Edge Browser Update A confirmed bug in Microsoft Teams desktop client version 26072.519.4556.7438 is disabling the right-click paste option for users on Windows and macOS, with Microsoft attributing the root cause to a code regression introduced in a recent Microsoft Edge browser update. Users across organizations began reporting on…
-
OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations
OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations OpenAI has officially launched the expanded phase of its Trusted Access for Cyber program. Granting select organizations access to its specialized GPT-5.4-Cyber model to strengthen digital defenses across critical infrastructure, financial services, and open-source security communities. The program operates on a tiered trust model advanced AI cyber capabilities…
-
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character Apple is reportedly developing a software fix for a frustrating iOS 26 bug that has left some users entirely locked out of their iPhones for months. According to a recent report by The Register, Cupertino’s software engineers are scrambling to patch…
-
Researcher Uses Claude Opus to Build a Working Chrome Exploit Chain
Researcher Uses Claude Opus to Build a Working Chrome Exploit Chain Amidst the heated debate surrounding Anthropic’s recent announcement of its Mythos and Project Glasswing models, a security researcher has demonstrated the tangible cybersecurity implications of frontier AI. Moving beyond theoretical warnings, the researcher successfully utilized Claude Opus to construct a fully functional exploit chain…
-
Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say
Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal identifiable information (PII), including completed…
-
Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations
Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet’s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability to hijack TBK DVR…
-
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024,…
-
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. The vulnerability…
-
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, leaving users with no…
-
Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches
Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering repeated reboot loops after installation. Released on April 14, 2026, the cumulative update KB5082063 (OS…
-
Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network
Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates. Discovered and reported by security researchers…
-
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve unauthenticated, one-click…
-
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware A newly discovered piece of malware called ZionSiphon has raised serious concerns about the security of critical water infrastructure in Israel. The malware was built with a clear focus: to infiltrate and potentially sabotage Israeli water treatment and desalination systems, the very facilities responsible for providing…
-
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments A new wave of cyber attacks is hitting trucking carriers and freight brokers, and the goal is not just data theft. Criminals are breaking into logistics companies digitally to steal physical cargo shipments worth millions of dollars in the real world. Cargo theft is…
-
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users Google Chrome is the most widely used browser in the world, yet a sweeping new analysis reveals it offers users almost no protection against fingerprinting and data leaks that quietly expose their identity to websites and trackers. Published April 14, 2026, the…
-
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks A critical security vulnerability has been officially disclosed, affecting multiple versions of Enterprise and Cloud platforms. Tracked as CVE-2026-20204, this high-severity flaw carries a CVSS score of 7.1 and poses a significant threat to organizational networks. Discovered and reported by Splunk researcher Gabriel Nitu,…
-
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now!
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now! Google has rolled out a crucial security update for its Chrome browser, addressing 31 vulnerabilities that could leave systems exposed to severe cyber threats. Released on April 15, 2026, this Stable Channel update requires immediate attention from users worldwide, as the most severe flaws…
-
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader A newly uncovered attack campaign is tricking users into installing remote access software on their systems by disguising malware as a legitimate Adobe Acrobat Reader download. The attack uses a sophisticated chain of techniques — including in-memory execution, process masquerading, and privilege escalation — to…
-
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia’s commercial hosting ecosystem. Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers, spanning…
-
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. Known as Triad Nexus, the group has rebuilt its global fraud operation following U.S. Treasury sanctions, deploying over 175…
-
Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature
Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature Microsoft officially released security updates to address a significant vulnerability in Windows BitLocker. Tracked as CVE-2026-27913, this security feature bypass vulnerability was discovered by security researcher Alon Leviev in collaboration with the Microsoft STORM team. The flaw poses a substantial risk to enterprise device security architectures.…
-
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT A new ransomware family called JanaWare has begun targeting computer users in Turkey, relying on a customized version of the Adwind remote access trojan (RAT) to gain a foothold on victims’ systems. This campaign stands out because it combines a known cross‑platform RAT with fresh…
-
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack Microsoft has released patch Tuesday security updates to address a newly discovered zero-day vulnerability in the Microsoft Defender Antimalware Platform. Disclosed on April 14, 2026, the flaw is tracked as CVE-2026-33825 and carries an “Important” severity rating. If successfully exploited, this elevation-of-privilege vulnerability allows an attacker…
-
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked to software signed by a company called Dragon Boss Solutions LLC. The…
-
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware A dangerous malware campaign has been silently targeting cryptocurrency users by hiding inside a fake version of Proxifier, a popular proxy software tool. Threat actors set up a GitHub repository designed to look like a legitimate Proxifier download, but the installer bundled inside…
-
Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online
Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online Rockstar Games has confirmed a data breach after the notorious hacking group ShinyHunters exploited a third-party integration to access the company’s internal Snowflake data warehouse, ultimately leaking over 78.6 million records on April 14, 2026. The breach did not stem from a direct attack…
-
Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors
Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors Anthropic’s Claude AI is facing a fresh wave of user-reported disruptions on April 13, 2026, with hundreds of users encountering intermittent HTTP 500 internal server errors across claude.ai, the API, and Claude Code, even as Anthropic’s official status page continues to show “All…
-
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms’ own servers. What…
-
Mozilla Criticizes Microsoft for Installing Copilot on Windows Without User Consent
Mozilla Criticizes Microsoft for Installing Copilot on Windows Without User Consent Mozilla has publicly criticized Microsoft for deploying its AI assistant, Copilot, onto Windows systems without user consent, a practice the Firefox maker describes as prioritizing corporate revenue over user rights. In a blog post titled “Old Habits Die Hard,” Mozilla accused Microsoft of using…
-
Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset
Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset Microsoft has officially acknowledged that recent security updates for Windows 11 are causing the “Reset this PC” (Push-button reset) recovery feature to fail. The issue was confirmed in the release notes for the March 2026 hotpatch updates, affecting systems running the latest operating system version.…
-
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access A critical security flaw found in a widely used WordPress plugin is putting thousands of websites at serious risk worldwide. Tracked as CVE-2026-1492, this vulnerability affects the User Registration & Membership plugin for WordPress and lets attackers completely bypass the login process to…
-
WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov
WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov Telegram founder Pavel Durov has accused WhatsApp of perpetrating what he calls “the biggest consumer fraud in history,” alleging that the platform’s widely marketed end-to-end encryption (E2EE) claims are fundamentally misleading, leaving the private messages of billions of users exposed on unencrypted…
-
OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately
OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately OpenAI has disclosed a security incident tied to the compromise of Axios, a widely used third-party JavaScript developer library, as part of a broader software supply chain attack detected on March 31, 2026. While the company confirmed no user data, API keys, or systems were…
-
Google Launches Gmail End-to-End Encryption for Android and iOS
Google Launches Gmail End-to-End Encryption for Android and iOS Google has officially rolled out End-to-End Encryption (E2EE) for the Gmail application on Android and iOS devices. This major update targets users utilizing Gmail client-side encryption. It allows organisations to handle sensitive data confidentially directly from their smartphones or tablets. The feature ensures compliance with strict…
-
Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move
Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move Google officially announced the public rollout of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146. According to the Google Account Security and Chrome teams, this major security update aims to eliminate session hijacking, a primary method for attackers to compromise user accounts. The feature…
-
Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns
Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns In recent years, Endpoint Detection and Response (EDR) killers have become a standard, highly effective weapon in modern ransomware intrusions. Before launching their file-encrypting malware, cybercriminals routinely deploy specialized tools to bypass security software. According to a comprehensive new report by ESET Research,…
-
Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies
Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies A single threat actor compromised nine Mexican government agencies and stole hundreds of millions of citizen records in a highly sophisticated cyberattack. The campaign, which ran from late December 2025 through mid-February 2026, highlights a dangerous shift in the modern threat landscape. Researchers at Gambit…
-
Anthropic Launches Claude Beta for Word, Bringing AI-Powered Editing to Microsoft Docs
Anthropic Launches Claude Beta for Word, Bringing AI-Powered Editing to Microsoft Docs Anthropic has officially launched Claude for Word in public beta, bringing its AI assistant directly into Microsoft Word as a native sidebar add-in for Team and Enterprise users on both Mac and Windows platforms. The integration marks a significant step in Anthropic’s push…
-
CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools
CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools The cpuid-dot-com website, home to widely used system utilities CPU-Z and HWMonitor, is at the center of an active supply chain security incident. Users downloading HWMonitor 1.63 or CPU-Z ZIPs since early April have reportedly received trojanized installers capable of dropping malicious DLLs, evading antivirus…
-
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf A fake developer extension published on the OpenVSX marketplace is silently spreading a known malware strain called GlassWorm to every code editor installed on a developer’s machine. The malicious package disguises itself as a legitimate productivity tool and uses a compiled native binary to…
-
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action Austin, Texas, United States, April 9th, 2026, CyberNewswire Built by a veteran security team and led by a former Google and Mandiant executive, Mallory delivers intelligence that drives action for enterprise security teams. Mallory is launching a AI-native threat intelligence platform, purpose-built…
-
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based attackers to gain full administrative control of exposed network devices easily. Formally tracked as CVE-2026-33784, this vulnerability has…