🛡

Cybersecurity

540 articles · Coverage updated continuously

Cybersecurity 540 articles
CISA Alerts: cPanel, Linux Exploits & AI Phishing Top Weekly Threats
Cybersecurity

This week, critical vulnerabilities moved from discovery to active exploitation, underscoring a rapidly escalating threat landscape. A severe flaw in cPanel and WebHost Manager is under widespread attack, alongside a critical Linux kernel privilege escalation added to CISA's Known Exploited Vulnerabilities catalog. These incidents highlight a shift towards sophisticated, multi-vector attacks targeting foundational infrastructure and supply chains.

May 04, 2026 Thehackernews 7 min
cPanel Zero-Day: Over 40,000 Servers Compromised in Active Exploitation
Cybersecurity

Over 40,000 servers are believed to have been compromised following the rapid, widespread exploitation of a critical cPanel zero-day vulnerability (CVE-2026-41940). This flaw allows unauthenticated attackers to gain administrative access, posing severe risks to host systems, configurations, databases, and websites managed by the popular platform. The ongoing campaign highlights the urgent need for patching amid escalating cyber threats.

May 04, 2026 Securityweek 3 min
Global Sting Dismantles Crypto Scam Threat, Seizes $701M
Cybersecurity

A landmark international operation, spearheaded by U.S., Chinese, and UAE authorities, has disrupted a vast network of cryptocurrency investment fraud, leading to 276 arrests and the seizure of $701 million. This coordinated crackdown targeted "pig butchering" scam centers primarily in Southeast Asia, which lured victims into bogus crypto investments and exploited trafficked labor.

May 04, 2026 Thehackernews 7 min
Sponsored
Telegram Mini Apps Exploited: Crypto Scams, Android Malware Surge
Cybersecurity

A sophisticated, large-scale fraud operation is leveraging Telegram's seemingly benign Mini App feature to orchestrate extensive crypto scams, impersonate major brands, and deliver Android malware. This illicit platform, dubbed FEMITBOT, creates highly convincing in-app experiences directly within the messaging platform, significantly expanding the attack surface for unsuspecting users.

May 03, 2026 Bleepingcomputer 3 min
CISA Flags Critically Exploited Linux Root Flaw in KEV Catalog
Cybersecurity

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning, adding a nine-year-old Linux local privilege escalation (LPE) flaw, tracked as CVE-2026-31431 and dubbed 'Copy Fail,' to its Known Exploited Vulnerabilities (KEV) catalog. This critical vulnerability allows unprivileged local users to gain root access and is actively being exploited in the wild. The bug, impactful across numerous Linux distributions and cloud environments, highlights a severe threat to system integrity and container security.

May 03, 2026 Thehackernews 4 min
🛡
Cybersecurity
Cybersecurity

A critical cPanel authentication bypass vulnerability (CVE-2026-41940) is being mass-exploited as a zero-day, leading to widespread "Sorry" ransomware attacks. This ongoing campaign targets web hosting control panels, encrypting data on tens of thousands of compromised servers and demanding payment for decryption keys.

May 03, 2026 Bleepingcomputer 3 min
Fast16: US Cyber Sabotage Against Iran Pre-Stuxnet Revealed
Cybersecurity

Newly reverse-engineered malware, dubbed Fast16, has been identified as a highly sophisticated state-sponsored cyberweapon, likely originating from the United States. Deployed against Iran years prior to the infamous Stuxnet attack, Fast16 uniquely manipulated high-precision calculations to induce subtle yet catastrophic failures in critical systems. This revelation sheds new light on the early history of nation-state cyber capabilities and offensive operations.

May 02, 2026 Schneier 1 min
🛡
Cybersecurity
Cybersecurity

A sophisticated new phishing kit dubbed Bluekit has emerged, equipped with an integrated AI assistant and robust automation features designed to streamline credential theft and session hijacking. Discovered by Varonis, this rapidly evolving kit offers a comprehensive suite of tools for attackers, signaling a potential shift in the sophistication of readily available phishing tools.

May 02, 2026 Securityweek 3 min
ALERT: 30,000 Facebook Accounts Compromised via Google AppSheet
Cybersecurity

A sophisticated phishing campaign, codenamed "AccountDumpling," has successfully compromised approximately 30,000 Facebook accounts by leveraging Google AppSheet as a "phishing relay." This Vietnamese-linked operation bypassed traditional spam filters, targeting Facebook Business owners with convincing Meta Support lures to steal credentials and 2FA codes. The stolen accounts are subsequently sold on illicit underground marketplaces.

May 02, 2026 Thehackernews 4 min
Cybercrime Double Agent: Ransomware Negotiator Worked for Gang
Cybersecurity

A shocking revelation has rocked the cybersecurity community as a ransomware negotiator pleaded guilty to secretly operating as a double agent for a criminal gang. This individual was ostensibly hired to help victims recover from attacks but was simultaneously aiding the very perpetrators.

May 02, 2026 Schneier 1 min
Dev Supply Chain Attack Hits SAP, PyPi, NPM; Steals Credentials
Cybersecurity

A sophisticated supply chain attack, dubbed 'Mini Shai-Hulud,' has compromised over 1,800 developers across the PyPi, NPM, and PHP ecosystems. Attributed to TeamPCP, the campaign injected malicious code into popular packages like SAP NPM, Lightning PyPi, and intercom-client, designed to exfiltrate critical credentials and secrets.

May 02, 2026 Securityweek 3 min
Stealthy Python Backdoor Deep#Door Enables Windows Espionage
Cybersecurity

A sophisticated new Python-based backdoor, dubbed Deep#Door, has been identified providing attackers with persistent remote command execution and extensive surveillance capabilities on Windows systems. This stealthy malware employs multi-layered persistence and advanced evasion techniques to bypass security controls and operate with a minimal forensic footprint. Its dual capability for espionage and destructive operations poses a significant threat to targeted organizations.

May 02, 2026 Securityweek 3 min