Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor …

Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the Microsoft.AspNetCore.DataProtection NuGet package. The out-of-band release was prompted after customers …

Unauthorized Group Gains Access to Anthropic’s Exclusive Cyber Tool Mythos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of unauthorized users has reportedly breached access controls surrounding Claude Mythos Preview, Anthropic’s powerful and closely guarded AI-driven cybersecurity tool, raising serious concerns about third-party vendor security and the risks of placing advanced offensive AI capabilities in the …

BreachLock Named Representative Vendor in the 2026 Gartner Market Guide for Adversarial Exposure Validation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, United States, April 21st, 2026, CyberNewswire BreachLock, a global leader in offensive security, today announced it has been named a representative vendor in the 2026 Gartner Market Guide for Adversarial Exposure Validation.   This recognition marks the first time BreachLock …

The Ungoverned Workforce: Cybersecurity Insiders Finds 92% Lack Visibility Into AI Identities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Washington D.C., USA, April 21st, 2026, CyberNewswire Cybersecurity Insiders, in collaboration with Saviynt, has released new research indicating that AI identities are increasingly operating within core enterprise systems, often without established governance or visibility. The study finds that while 71% …

Hackers Abuse GitHub Issue Notifications to Phish Developers Through Malicious OAuth Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated phishing technique that targets software developers by abusing GitHub’s own notification system to deliver malicious OAuth app authorization requests. This attack is particularly dangerous because it uses GitHub’s trusted infrastructure, making it extremely hard …

CISA Warns of Cisco Catalyst SD-WAN Manager Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added three critical Cisco Catalyst SD-WAN Manager vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to act immediately. All three flaws were added on April 20, 2026, with a tight remediation deadline of …

6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than 6,000 internet-exposed Apache ActiveMQ instances are still vulnerable to CVE-2026-34197. This newly tracked security flaw has now been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog. The exposure data comes from The Shadowserver Foundation, which …

Gentlemen RaaS Attacking Windows, Linux With additional locker written in C for ESXi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware-as-a-service (RaaS) operation known as “The Gentlemen” has emerged as a serious threat to corporate networks worldwide. Since appearing around mid-2025, this group has rapidly grown into a well-organized criminal platform, publicly claiming over 320 victims, with most …

AI-Powered Exploitation May Collapse the Patch Window for Defenders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence is reshaping cybercrime in ways that defenders can no longer treat as distant or theoretical. New frontier AI models are showing a growing ability to find software flaws, understand attack paths, and help move an intrusion from one …