pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes …

Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. The finding, …

Apache HTTP Server Exposes Millions of Servers to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026. All users running …

New MicroStealer Malware Actively Attacking Telecom & Education Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 A new infostealer malware called MicroStealer has quietly entered the threat landscape and is already showing a worrying reach. First spotted in December 2025, the malware has picked up speed fast, showing up across sandbox environments within …

New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 A newly identified botnet called xlabs_v1 has been found targeting Minecraft game servers by exploiting Android devices with the Android Debug Bridge (ADB) port left open and exposed to the internet. The botnet is a modified version …

CISA Warns of Linux Kernel 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel zero-day vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning federal agencies and organizations worldwide to patch immediately or discontinue use of affected …

Apache MINA Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 The Apache MINA project has issued urgent security updates to address two critical vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Developers relying on this network application framework are strongly urged to update …

CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, …

Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 3, 2026 Microsoft Defender triggered widespread false positive alerts after a faulty security update caused it to flag two legitimate DigiCert root certificates as malicious, potentially disrupting SSL/TLS validation and code-signing operations across enterprise environments worldwide. A Defender antimalware …

Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 Cybersecurity giant Trellix has disclosed a significant security incident involving unauthorized access to a portion of its source code repository. The company confirmed the breach in an official statement published on its website, stating it immediately engaged …