May 2, 2026 The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software. These flaws allow attackers to potentially crash …
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace
May 2, 2026 Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October 2025, security researchers have tracked two distinct …
Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign
May 2, 2026 A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional …
cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised
May 2, 2026 A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to …
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
May 1, 2026 Torrance, United States / California, May 1st, 2026, CyberNewswire Criminal IP partners with Securonix to integrate Criminal IP’s Threat Intelligence into ThreatQ, allowing organizations to incorporate external …
EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins
May 1, 2026 A new and well-planned malware campaign has been actively targeting enterprise administrators, DevOps engineers, and security analysts by hijacking their everyday search habits. Rather than using mass …
New Spyware Platform Lets Buyers Rebrand and Resell Android Surveillance Malware
May 1, 2026 A new Android spyware tool is being sold openly on the internet, and it comes with something far more dangerous than its surveillance features alone. For a …
Attackers Abuse CAPTCHA and ClickFix Tactics to Boost Credential Theft Campaigns
Cybercriminals are no longer relying on simple email tricks alone. Across the first quarter of 2026, attackers have been sharpening their approach by using CAPTCHA pages and ClickFix techniques to …
New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers
May 1, 2026 A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat …
Ransomware Victims Jump to 7,831 as AI Crime Tools Scale Global Attacks
May 1, 2026 The ransomware threat has reached a new and alarming level. According to Fortinet’s newly released 2026 Global Threat Landscape Report, the number of confirmed ransomware victims worldwide …


