cPanel Warns of Critical Authentication Flaw – Emergency Patch Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) …

New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 BlobPhish Browser-Based Phishing Attack A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining …

Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub’s internal git infrastructure that could have allowed any authenticated user to compromise backend servers, access millions of private repositories, and, in the case of GitHub Enterprise Server (GHES), …

Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Microsoft has officially acknowledged a known issue in its April 2026 Windows 11 cumulative update: Remote Desktop Protocol (RDP) security warning dialogs may render incorrectly on certain system configurations, a significant usability concern given that the warnings …

Chinese Silk Typhoon Hacker Extradited to the U.S. from Italy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A Chinese national tied to one of the most damaging state-sponsored hacking campaigns in recent history has been extradited to the United States from Italy. Xu Zewei, 34, a citizen of the People’s Republic of China, landed …

WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 WhatsApp is currently developing an independent cloud backup system designed to give users more direct control over their chat histories. This upcoming feature will allow users to store their backups securely on WhatsApp’s native servers. The update …

New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A critical zero-click authentication coercion vulnerability, tracked as CVE-2026-32202, stemming from an incomplete patch for a Windows Shell security feature bypass actively weaponized by the Russian APT28 threat group. Microsoft confirmed active exploitation of the flaw and released …

New Silver Fox Campaign Uses Fake Tax Audit Alerts and Software Updates to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Silver Fox, a China-based threat group has launched a new wave of attacks targeting businesses and individuals across Asia, using fake tax audit notifications and counterfeit software update alerts to install dangerous malware on victim systems. The …

Chinese-Backed Smishing Services Use OTT Messaging and SMS to Scale Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A wave of large-scale phishing campaigns backed by Chinese-language services is quietly targeting people around the world, using everyday messaging apps to steal personal and financial credentials. These operations have grown well beyond regional limits, making them …

Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the …