Aggregator
QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise
A new and previously undocumented Linux threat has emerged, targeting software developers in a way that could put entire supply chains at risk. Named Quasar Linux, or QLNX, this malware operates as a full-featured remote access trojan built specifically for Linux systems. It combines stealth techniques with targeted credential theft, making it one of the […]
The post QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise appeared first on Cyber Security News.
Тихая месть Безоса: пока SpaceX взрывает прототипы, Blue Origin готовит рабочий лунный корабль
ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users
Samsung mobile security advisory (AV26-429)
New CISA initiative aims for critical infrastructure to operate offline during cyberattacks
WatchGuard security advisory (AV26-428)
Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison
A Latvian national operating out of Moscow was sentenced to 102 months in federal prison for his central role in a sprawling Russian ransomware syndicate. Deniss Zolotarjovs, 35, served as a primary extortionist and negotiator for a highly organized cybercriminal network that attacked over 54 companies worldwide. The United States Justice Department announced the sentencing, […]
The post Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison appeared first on Cyber Security News.
Argo CD’s ServerSideDiff Vulnerability Enables Kubernetes Secret Extraction
A critical cybersecurity vulnerability has been uncovered in Argo CD, a widely used declarative GitOps continuous delivery tool for Kubernetes environments. Tracked as CVE-2026-43824, this high-severity flaw allows low-privileged users to extract plaintext Kubernetes Secrets directly from a cluster. According to security analysis from Devoriales, the vulnerability carries a severe CVSS score of 9.6, as […]
The post Argo CD’s ServerSideDiff Vulnerability Enables Kubernetes Secret Extraction appeared first on Cyber Security News.
Taiwan High Speed Rail Hacked Using Radio Signal Spoofing Attack That Halted Three Trains
On the final night of the Qingming Festival holiday, three Taiwan High Speed Rail trains were forced into emergency stops due to a sophisticated radio signal spoofing attack. The malicious transmission triggered false alarms across the network, causing a nearly hour-long delay for passengers. Authorities have since apprehended a 23-year-old college student in connection with […]
The post Taiwan High Speed Rail Hacked Using Radio Signal Spoofing Attack That Halted Three Trains appeared first on Cyber Security News.
New MajorDoMo RCE Vulnerability Exposes Servers to Code Execution Attacks
A newly disclosed flaw exposes internet-facing MajorDoMo servers to unauthenticated remote code execution via a broken authentication flow and unsafe dynamic PHP evaluation. The vulnerability (CVE-2026-27174) stems from the /admin.php request flow, where improper handling of unauthorized access allows execution to continue even after a redirect, effectively bypassing access controls. That continued execution exposes an […]
The post New MajorDoMo RCE Vulnerability Exposes Servers to Code Execution Attacks appeared first on Cyber Security News.
52.3 Bitcoin and a Suburban Search Warrant: Inside One of Australia's Biggest Crypto Seizures
Пароли больше не требуются. В популярной CMS нашли лазейку для захвата сайтов пачками
CVE-2026-5937 | Foxit PDF Editor/PDF Reader prior 13.2.4 std::invalid_argument uncaught exception (EUVD-2026-25823 / Nessus ID 310407)
CVE-2010-1869 | Artifex Gpl Ghostscript 8.70 Parser parser memory corruption (EDB-14406 / Nessus ID 46680)
Akamai Is the 2026 Gartner® Peer Insights™ Customers’ Choice for API Protection
AI Survey: 50% of Organizations Struggle to Maintain Latency at Scale
When DNSSEC goes wrong: how we responded to the .de TLD outage
New Phishing-to-RMM Attacks: How Analysts Can Detect Trusted-Tool Abuse Early
ANY.RUN researchers uncovered a phishing-to-RMM campaign in which attackers use fake Microsoft, Adobe, and OneDrive pages to deliver legitimate remote management tools such as ScreenConnect and LogMeIn Rescue. Detection is difficult because the payload and infrastructure can look legitimate in isolation. Analysts need to connect the full chain, from phishing lure to RMM execution and outbound connections, […]
The post New Phishing-to-RMM Attacks: How Analysts Can Detect Trusted-Tool Abuse Early appeared first on Cyber Security News.