Tag: cyber-security-news
-
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations A nation-state malware known as Kazuar has resurfaced with a far more dangerous design than anyone expected. What once started as a relatively standard backdoor has now grown into a fully modular, peer-to-peer botnet specifically engineered for long-term, covert espionage against high-value government and diplomatic…
-
VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root
VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and patched on May 14, 2026, under security advisory VMSA-2026-0003.…
-
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks A state-aligned hacking group known as FrostyNeighbor has resurfaced with a fresh wave of cyberattacks targeting government organizations in Ukraine, using a carefully designed infection chain that is harder than ever to detect. The group, active since at least 2016, has a long history of…
-
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now! Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsing the web on an outdated version leaves your entire system wide open…
-
Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks
Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors…
-
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker Attackers are now abusing a fresh Langflow vulnerability to quietly steal cloud keys and turn victim systems into workers for a new NATS based botnet. This campaign shows how a single exposed AI workflow tool can become the start of large scale credential theft…
-
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak Packagist is sounding the alarm for PHP developers everywhere. A flaw in Composer, the widely used PHP dependency manager, briefly caused GitHub authentication tokens to leak into publicly visible CI logs, raising urgent concerns about credential exposure across thousands of active software projects around the…
-
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading Iran-linked hackers have been quietly breaking into networks around the world, and their latest campaign is more calculated than anything we have seen from them before. The group known as Seedworm, also tracked as MuddyWater, spent the first quarter of 2026 targeting at least…
-
Windows DNS Client Vulnerability Enables Remote Code Execution Attacks
Windows DNS Client Vulnerability Enables Remote Code Execution Attacks A newly disclosed vulnerability in the Microsoft Windows DNS Client could let attackers silently execute malicious code across enterprise networks, exposing a massive attack surface. Officially designated as CVE-2026-41096, this critical security flaw carries a severe CVSS score of 9.8 out of 10. By simply returning…
-
Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks
Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web…
-
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks A serious security flaw has been found in Exim, one of the most widely deployed mail transfer agents on the internet today. The vulnerability, tracked as EXIM-Security-2026-05-01.1, allows a remote attacker to corrupt server memory and potentially execute malicious code without needing any special privileges or…
-
Google Enhances Android Mobile Security with New AI-Powered Protections
Google Enhances Android Mobile Security with New AI-Powered Protections Android smartphones have become the go-to device for billions of people around the world. From banking and messaging to storing personal photos and sensitive documents, people rely on them for almost everything. That reliance has made mobile devices a prime target for scammers, cybercriminals, and threat…
-
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2 Microsoft pushed out a significant cumulative update for Windows 11 on May 12, 2026, covering both version 25H2 and version 24H2. The update, identified as KB5089549, brings OS Builds 26200.8457 and 26100.8457 to users running these versions. It bundles the latest security fixes alongside…
-
Top 10 Best Data Loss Prevention Software in 2026
Top 10 Best Data Loss Prevention Software in 2026 In 2026, data is the undisputed lifeblood of the modern enterprise. As organizations shift completely to decentralized, multi-cloud architectures, the challenge of securing sensitive information—such as Intellectual Property (IP), Personally Identifiable Information (PII), and Protected Health Information (PHI)—has grown exponentially. It is no longer enough to…
-
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks A newly disclosed security vulnerability in Microsoft Teams could allow attackers to spoof local devices, raising concerns for enterprises and individual users who rely on the platform for daily communications. Microsoft disclosed CVE-2026-32185 on May 12, 2026, as part of its coordinated May 2026 Patch Tuesday…
-
Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks
Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks A serious cluster of vulnerabilities has been uncovered in PHP’s core string processing and ext-soap components, putting numerous web servers at immediate risk of total takeover. While the SOAP extension has a notorious history of memory corruption flaws, this latest discovery crosses the red line…
-
Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers
Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag Manager (GTM) containers, turning…
-
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. In May 2026, a malicious version of the Checkmarx Jenkins AST plugin was quietly published to the…
-
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely gain full shell access without victim…
-
TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps
TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps A dangerous Android banking malware known as TrickMo has resurfaced with a powerful new variant, and this time it is more stealthy, more capable, and harder to stop than ever before. The threat is actively targeting users of banking apps, digital wallets, and authenticator applications…
-
Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data
Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data A long-active information stealer is making headlines again, and this time it is targeting more than just passwords. Vidar malware, a credential-harvesting tool in circulation since late 2018, has been observed running through a sophisticated multi-stage attack chain designed to slip past modern security…
-
Google reCAPTCHA Update Blocks Privacy-Focused Android Users From Sites
Google reCAPTCHA Update Blocks Privacy-Focused Android Users From Sites Google has rolled out a significant update to its reCAPTCHA verification system that fundamentally alters how websites verify human traffic. Announced on April 22 at the Google Cloud Next 2026 conference, the new mechanism operates through Google’s Cloud Fraud Defense tool and introduces a mandatory QR…
-
JDownloader Downloader Hacked to Infect Users With New Python RAT
JDownloader Downloader Hacked to Infect Users With New Python RAT JDownloader, the popular open-source download manager trusted by millions of users worldwide, was at the center of a serious supply chain attack in early May 2026. Attackers quietly compromised the official jdownloader.org website and replaced legitimate installer download links with malicious files carrying a fully…
-
10 Best Full Disk Encryption Tools in 2026
10 Best Full Disk Encryption Tools in 2026 Full Disk Encryption (FDE) is a security feature that encrypts the entire contents of a disk drive, ensuring that all data stored on the drive is protected from unauthorized access, even if the device is physically stolen. FDE uses robust encryption algorithms to encrypt data on the…
-
Top 10 Best Interactive Malware Analysis Tools in 2026
Top 10 Best Interactive Malware Analysis Tools in 2026 As we navigate through 2026, the cybersecurity landscape has never been more complex. Threat actors are actively leveraging advanced AI, highly evasive techniques, and fileless architectures to bypass traditional security controls. For security operation centers (SOCs), incident responders, and threat hunters, static analysis alone is no…
-
New cPanel and WHM Flaws Enable Code Execution, DoS Attacks
New cPanel and WHM Flaws Enable Code Execution, DoS Attacks cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection,…
-
TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules
TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules A highly sophisticated Brazilian banking trojan named TCLBANKER, tracked under the campaign REF3076, this malware represents a major update to the older Maverick and SORVEPOTEL families. It stands out because it uses a fake, signed Logitech installer to infect systems and spreads automatically via…
-
NVIDIA Data Breach Reportedly Exposes Personal Information of GeForce Users
NVIDIA Data Breach Reportedly Exposes Personal Information of GeForce Users A data breach at GFN.AM, an authorized NVIDIA GeForce NOW cloud gaming service provider operating under “GFN CLOUD INTERNET SERVICES” LLC, has exposed personal information belonging to registered users. The company disclosed the incident on May 5, 2026, revealing that unauthorized access to its database…
-
Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident
Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident Let’s Encrypt temporarily suspended all certificate issuance on May 8, 2026, after engineers identified a critical issue involving a cross-signed certificate linking the organization’s Generation X root to its upcoming Generation Y root infrastructure. The incident triggered a complete shutdown of issuance across both production…
-
Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information
Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft’s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as…
-
New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials
New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials A new backdoor called PamDOORa has emerged as a serious and growing threat to Linux systems, targeting one of the most trusted components of the operating system to silently steal SSH credentials. The malware was advertised for sale on a Russian-speaking cybercrime forum called Rehub,…
-
Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models
Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline built around Anthropic’s Claude Mythos…
-
Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets
Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets Spring Cloud Config provides crucial server-side and client-side support for externalized configuration in distributed systems. Recently, the Spring development team disclosed four security vulnerabilities impacting the Spring Cloud Config Server. These flaws range from medium to critical severity, exposing environments to unauthorized arbitrary file access, cloud…
-
Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released
Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major Linux distributions, with a public exploit…
-
Multiple Critical Vulnerabilities Patched in Next.js and React Server Components
Multiple Critical Vulnerabilities Patched in Next.js and React Server Components Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the App Router, as well as React Server Components…
-
New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks
New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately. At the time of disclosure, Ivanti confirmed active exploitation of CVE-2026-6973, a vulnerability that requires…
-
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems A new threat intelligence report has revealed that an unknown group of hackers used a commercial AI tool to target the systems of a municipal water and drainage utility in Monterrey, Mexico. The attack, which took place in January 2026, marks one of…
-
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally A major security flaw has placed Ollama, one of the most widely used platforms for running local AI models, at risk of a high-profile exposure event. The issue, dubbed “Bleeding Llama,” allows unauthenticated attackers to access the Ollama process and extract sensitive data directly from memory,…
-
Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP
Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP Microsoft is expanding interoperability in its mobile communication ecosystem by allowing Microsoft Teams users on Android devices to join third-party meetings via the Session Initiation Protocol (SIP). Recently detailed on the Microsoft 365 roadmap, this upcoming feature addresses a major enterprise demand for…
-
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures A new wave of cyberattacks is putting macOS users in the crosshairs, and this time the bait looks almost too familiar. Attackers are disguising their malware as helpful disk cleanup tools and system utilities, tricking people into running dangerous commands directly on…
-
Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits
Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits Distributed Denial of Service (DDoS) campaign targeted a large-scale user-generated content platform, unleashing over 2.45 billion malicious requests in just five hours. Rather than relying on brute-force methods, the attackers distributed traffic across 1.2 million unique IP addresses. This structural shift exposed a fundamental…
-
Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse
Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse Cloud identity security relies heavily on Microsoft Entra ID (formerly Azure AD) Conditional Access. It acts as the primary digital gatekeeper, checking user locations, calculating risk scores, and verifying device health before granting access. However, an authorized red team engagement by Howler Cell…
-
Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector
Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector The aviation and aerospace sector has become one of the most actively targeted industries by ransomware operators and data extortion groups in 2025 and 2026. From passenger-processing platforms to satellite-dependent navigation systems, attackers are finding that disrupting even a single vendor in the…
-
Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access
Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows unauthenticated attackers to execute arbitrary…
-
Low Noise, High Confidence: Optimizing SOC Costs with Better Threat Intelligence
Low Noise, High Confidence: Optimizing SOC Costs with Better Threat Intelligence Robust defense systems are built on a clear understanding of current threats and the ability to translate it into consistent decisions and measurable outcomes at optimal cost. High-performing SOCs achieve this by eliminating unnecessary work and operationalizing threat data. At the core of this model lies threat intelligence that is: Relevant to active threats Actionable within existing workflows Curated to reduce false alerts Not all threat data sources meet these…
-
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications. The update is highly recommended for all systems using GnuTLS, as it addresses memory corruption, authentication bypasses, and certificate validation errors. Four vulnerabilities discovered…
-
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine A fake website claiming to offer an official macOS version of the popular text editor Notepad++ has been making rounds online, raising serious cybersecurity concerns across the tech community. The site, operating under the domain notepad-plus-plus-mac.org, falsely presents itself as the official release…
-
Critical Android Zero-Click Vulnerability Grants Remote Shell Access
Critical Android Zero-Click Vulnerability Grants Remote Shell Access Google has published the May 2026 Android Security Bulletin, alerting the ecosystem to a highly severe remote code execution (RCE) flaw. Tracked as CVE-2026-0073, this critical vulnerability resides deep within the core Android System component. It allows an attacker to gain remote shell access without requiring a…
-
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes a direct step…
-
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. The finding, disclosed on April 29 by PaloAltoNtwks…
-
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026. All users running version 2.4.66 or…
-
CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks
CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating that threat actors are actively abusing it…
-
Critical MOVEit Vulnerabilities Enables Authentication Bypass
Critical MOVEit Vulnerabilities Enables Authentication Bypass Progress Software has issued a critical security bulletin for its MOVEit Automation platform. This April 2026 alert warns of two highly severe vulnerabilities that could allow attackers to bypass security checkpoints and gain full system control. MOVEit Automation is widely used by enterprises to manage and automate secure file…
-
Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed
Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed The way cyberattacks are launched has fundamentally changed. Threat actors are no longer spending months hunting for software flaws by hand. With artificial intelligence in their toolkit, they can now discover and exploit zero-day vulnerabilities in minutes, placing organizations across every sector…
-
FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root
FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this vulnerability allows a local network attacker to execute arbitrary code as root, granting them complete control over the compromised machine. Discovered by Joshua…
-
Email Bombing and Fake IT Support Calls Fuel New Microsoft Teams Phishing Attacks
Email Bombing and Fake IT Support Calls Fuel New Microsoft Teams Phishing Attacks A new wave of cyberattacks is targeting employees through a combination of inbox flooding and fake IT support contacts on Microsoft Teams, tricking users into handing over remote access to their own devices. These attacks have been growing steadily since the start…
-
Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository
Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository Cybersecurity giant Trellix has disclosed a significant security incident involving unauthorized access to a portion of its source code repository. The company confirmed the breach in an official statement published on its website, stating it immediately engaged leading forensic experts upon discovering the intrusion.…
-
Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability
Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day exploit chain against an Indonesian defense-sector portal and ultimately pivoting to exfiltrate over 4GB of sensitive Chinese railway documents. The campaign’s…
-
Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data
Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software. These flaws allow attackers to potentially crash servers, corrupt memory, or leak sensitive information. Because Exim is one of the most widely used…
-
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive data theft campaigns. These groups operate…
-
Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign
Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional email security filters. By routing fully authenticated phishing lures through legitimate channels, the attackers successfully harvest credentials…
-
cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised
cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with attack activity traced as far back as…
-
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations Torrance, United States / California, May 1st, 2026, CyberNewswire Criminal IP partners with Securonix to integrate Criminal IP’s Threat Intelligence into ThreatQ, allowing organizations to incorporate external IP intelligence into their existing workflows, helping security teams accelerate analysis and response with more actionable context.…
-
EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins
EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins A new and well-planned malware campaign has been actively targeting enterprise administrators, DevOps engineers, and security analysts by hijacking their everyday search habits. Rather than using mass phishing or broad spam waves, threat actors behind this operation have carefully crafted a delivery chain…
-
China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign
China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign A China-aligned threat group has been carrying out a carefully planned espionage campaign against government agencies and critical infrastructure across Asia. The group, tracked under the temporary designation SHADOW-EARTH-053, has been active since at least December 2024, quietly targeting organizations in at least…
-
New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims’ Phone Bills
New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims’ Phone Bills A newly documented scam campaign is using fake CAPTCHA pages to silently trigger dozens of international SMS messages from victims’ mobile phones, leaving them with unexpected charges on their phone bills. What looks like a routine “prove you’re human” step online…
-
Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets
Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets Wireshark, the world’s most widely used open-source network protocol analyzer, has released a major security update addressing over 40 vulnerabilities, several of which enable arbitrary code execution through malformed packet injection or malicious capture files. Organizations and individuals relying on Wireshark for network monitoring,…
-
Anthropic Launches Claude Security in Public Beta for Enterprise Customers
Anthropic Launches Claude Security in Public Beta for Enterprise Customers Anthropic has opened Claude Security to public beta for Claude Enterprise customers, bringing AI-powered vulnerability detection directly into production codebases without the need for custom tooling or API integrations. Claude Security leverages the Opus 4.7 model to perform end-to-end security analysis across your codebase. The…
-
Microsoft Windows 11 April 2026 Security Update Breaks Third-Party Backup Applications
Microsoft Windows 11 April 2026 Security Update Breaks Third-Party Backup Applications Microsoft’s April 2026 cumulative security update for Windows 11 is causing significant disruptions for users relying on third-party backup software, triggering an MS-DEFCON level 3 advisory from security patch analyst Susan Bradley at AskWoody. The problematic update, KB5083769, applies to Windows 11 versions 24H2…
-
OpenAI Releases 5-Point Action Plan to Strengthen AI-Powered Cyber Defense
OpenAI Releases 5-Point Action Plan to Strengthen AI-Powered Cyber Defense OpenAI has published a comprehensive cybersecurity action plan titled “Cybersecurity in the Intelligence Age: An Action Plan for Democratizing AI-Powered Cyber Defense,” outlining a five-pillar strategy to equip trusted defenders with advanced AI capabilities while preventing adversarial misuse. Artificial intelligence is fundamentally reshaping the cybersecurity…
-
CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs
CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs A new open-source project called CVE MCP Server is redefining how security teams triage vulnerabilities, transforming Anthropic’s Claude AI into a fully capable security analyst by giving it direct, correlated access to 27 intelligence tools spanning 21 external…
-
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent A new threat has quietly taken root in the software development world, using an AI coding assistant as an unknowing participant in a supply chain attack. A malicious npm package campaign called PromptMink surfaced after being introduced into an open-source autonomous crypto trading project through a…
-
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild In early 2026, two critical authentication bypass vulnerabilities in the popular open-source Qinglong task scheduler were actively exploited by hackers. According to Snyk security reports, unauthenticated attackers breached publicly accessible panels, achieving remote code execution to install a hidden, resource-draining cryptominer named .fullgc. Qinglong is a self-hosted…
-
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution A newly identified remote access trojan called KarstoRAT has been found in sandbox analyses and malware repositories since early 2026. The malware gives attackers a broad set of remote-control capabilities over compromised Windows machines, including webcam capture, audio recording, keylogging, screenshot theft, and…
-
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. The group first appeared in December 2025 and rapidly scaled its activity through February 2026,…
-
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files and demands payment for decryption, VECT 2.0 permanently destroys any file…
-
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group behind this activity is BlueNoroff, a financially motivated subgroup known for stealing digital assets. This…
-
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) ecosystem. System administrators and web hosting providers are…
-
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a…
-
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the matching Docker images on the GitHub…
-
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots Whenever someone uses Windows Remote Desktop, the operating system quietly saves visual fragments of the active session. As recently highlighted by SCYTHE Labs, attackers can easily extract these breadcrumbs and rebuild them into readable screenshots. This process requires no special privileges, takes just…
-
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override Cybersecurity researchers have recently disclosed three moderate-severity vulnerabilities in OpenClaw, an AI agent framework previously known as Clawdbot and Moltbot. Distributed as an npm package, these security flaws allow bypasses of policy enforcement, gateway configuration mutations, and host override attacks that could lead to credential exposure.…
-
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes Researchers from the Czech Technical University in Prague have developed a new adversarial malware generator targeting Linux ELF binaries. It achieves a 67.74% evasion rate against ML-based malware detectors while keeping the payload fully functional. Published on arXiv on April 24, 2026, the study by…
-
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography A well-known Iranian state-sponsored hacking group called OilRig, also tracked as APT34 and Helix Kitten, has been found hiding its command-and-control (C2) server configuration inside a regular-looking image file stored on Google Drive. The threat group used a technique called LSB (Least Significant Bit)…
-
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage payloads inside JPEG image files and TXT documents, making it much harder for security tools…
-
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities Multiple vulnerabilities in the CODESYS Control runtime, one of the world’s most widely adopted software-based programmable logic controller (Soft PLC) platforms. According to Nozomi Networks Labs researchers, by chaining these security flaws, an authenticated attacker can replace a legitimate industrial control application with a backdoored version, thereby…
-
Top 10 Best NDR (Network Detection and Response) Solutions in 2026
Top 10 Best NDR (Network Detection and Response) Solutions in 2026 In the modern enterprise, the network is the ultimate source of ground truth. As organizations accelerate their digital transformation and adopt complex, cloud-native security architectures, the traditional perimeter has dissolved. Threat actors routinely bypass endpoint defenses using compromised credentials, living-off-the-land (LotL) binaries, and highly…
-
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets The fast16 malware is a recently exposed sabotage‑capable threat designed to target extremely high‑value environments and ultra‑expensive systems with precision. It does not behave like common commodity malware that aims for broad infections, but instead focuses on select victims where disruption or long‑term control can cause…
-
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing A new open-source toolkit called pentest-ai-agents is redefining how security professionals leverage AI in penetration testing workflows, transforming Anthropic’s Claude Code into a fully specialized offensive security research assistant powered by 28 domain-specific subagents. Released by security researcher 0xSteph on GitHub, pentest-ai-agents is a collection of…
-
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to software developers. This activity follows a…
-
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued a full patch. Security researchers confirmed the flaw allowed threat actors to inject an invalid MWEB (MimbleWimble…
-
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented by Kaspersky application security specialist Haidar Kabibo at Black Hat Asia 2026 on…
-
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly valued targets for cybercriminals because they provide direct pathways into corporate networks. When compromised, these platforms allow threat actors…
-
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI representations are created equal. In December 2025, Anthropic transformed its San Francisco office into a live classified marketplace,…
-
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across…
-
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum — “Pay or Leak.” ADT, headquartered in Boca Raton, Florida, disclosed the incident via a Form 8-K…
-
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access State-sponsored threat actors are actively targeting Cisco Firepower devices by chaining known vulnerabilities to deploy a highly customized backdoor. Cisco Talos recently discovered that the espionage-focused threat group UAT-4356 is exploiting two n-day vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, to infiltrate Firepower Extensible…
-
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of several Chromium-based browsers. This undocumented behavior occurs without user consent, raising significant privacy and security concerns…
-
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weaponize this process. Hackers are now building fake CAPTCHA pages that trick users into…
-
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing web applications at a massive…