QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A new and previously undocumented Linux threat has emerged, targeting software developers in a way that could put entire supply chains at risk. Named Quasar Linux, or QLNX, this malware operates as a full-featured remote access trojan …

Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Latvian national operating out of Moscow was sentenced to 102 months in federal prison for his central role in a sprawling Russian ransomware syndicate. Deniss Zolotarjovs, 35, served as a primary extortionist and negotiator for a highly organized cybercriminal …

Argo CD’s ServerSideDiff Vulnerability Enables Kubernetes Secret Extraction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A critical cybersecurity vulnerability has been uncovered in Argo CD, a widely used declarative GitOps continuous delivery tool for Kubernetes environments. Tracked as CVE-2026-43824, this high-severity flaw allows low-privileged users to extract plaintext Kubernetes Secrets directly from …

Salesforce Marketing Cloud Vulnerability Opened Door to Email Data Exposure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A significant set of security vulnerabilities in Salesforce Marketing Cloud (SFMC) could have allowed attackers to read and expose private email data belonging to millions of users across hundreds of organizations. The flaws, now patched, were rooted …

Malicious OpenClaw DeepSeek Skill Exploits Agentic AI Workflows to Deliver RAT and Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A cleverly disguised malware campaign is targeting developers and AI-driven systems by hiding inside what looks like a legitimate plugin for an open-source AI framework. Security researchers have uncovered a threat that takes full advantage of how …

Iranian-Nexus Operation Targets Oman Ministries With Webshells, SQL Escalation, and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A sophisticated cyber operation linked to an Iranian-nexus threat actor has quietly worked through at least 12 Omani government ministries, stealing tens of thousands of citizen records and leaving persistent backdoors behind. The attackers used webshells, SQL …

Zero-Auth Flaw Exposes DoD Contractor to Cross-Tenant Data Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A severe zero-authorization vulnerability in Schemata’s API, an AI-powered virtual training platform holding active Department of Defense (DoD) contracts, recently exposed highly sensitive military training materials and U.S. service member records. Discovered by the open-source AI hacking …

Vimeo Data Breach Exposes 119,000 Users Unique Email Addresses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 In a significant supply chain security incident, the popular video hosting platform Vimeo has confirmed a data breach that exposed user information. Discovered in April 2026, the breach exposed 119,000 unique email addresses and other metadata. The …

Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 Cloud identity security relies heavily on Microsoft Entra ID (formerly Azure AD) Conditional Access. It acts as the primary digital gatekeeper, checking user locations, calculating risk scores, and verifying device health before granting access. However, an authorized …

Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows …