Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software. These flaws allow attackers to potentially crash servers, corrupt memory, or leak sensitive information. Because Exim is …

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive …

Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional email security filters. By routing fully authenticated phishing lures through …

cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with …

Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 Torrance, United States / California, May 1st, 2026, CyberNewswire Criminal IP partners with Securonix to integrate Criminal IP’s Threat Intelligence into ThreatQ, allowing organizations to incorporate external IP intelligence into their existing workflows, helping security teams accelerate …

EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 A new and well-planned malware campaign has been actively targeting enterprise administrators, DevOps engineers, and security analysts by hijacking their everyday search habits. Rather than using mass phishing or broad spam waves, threat actors behind this operation …

New Spyware Platform Lets Buyers Rebrand and Resell Android Surveillance Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 A new Android spyware tool is being sold openly on the internet, and it comes with something far more dangerous than its surveillance features alone. For a fee, anyone can buy it, put their own name and …

Attackers Abuse CAPTCHA and ClickFix Tactics to Boost Credential Theft Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are no longer relying on simple email tricks alone. Across the first quarter of 2026, attackers have been sharpening their approach by using CAPTCHA pages and ClickFix techniques to supercharge credential theft operations at an alarming scale. During Q1 …

New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 A newly discovered DDoS botnet is exploiting exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure. Security researchers at Darktrace identified the threat after capturing it on one of their honeypot systems. What …

Ransomware Victims Jump to 7,831 as AI Crime Tools Scale Global Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 The ransomware threat has reached a new and alarming level. According to Fortinet’s newly released 2026 Global Threat Landscape Report, the number of confirmed ransomware victims worldwide jumped to 7,831 in 2025, up from roughly 1,600 victims …