Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor to steal credentials and deliver ransomware without triggering endpoint security alerts. This alarming shift in attacker behavior highlights how freely available, trusted software …

Hackers Use MiningDropper to Deliver Infostealers, RATs, and Banking Malware on Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fast growing Android malware campaign is using a framework called MiningDropper to push far more dangerous threats onto phones disguised as normal apps. Researchers describe it as a multi stage delivery system that can lead to infostealers, remote access …

New RDP Alert After April 2026 Security Update Warns of Unknown Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has rolled out a significant behavioral change to the Windows Remote Desktop Connection application (MSTSC) as part of its April 2026 Patch Tuesday security update, introducing new warning dialogs designed to protect users from phishing attacks that exploit Remote …

Hackers Use FUD Crypt to Generate Microsoft-Signed Malware With Built-In Persistence and C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered malware-as-a-service platform called FUD Crypt is giving cybercriminals an easy way to build sophisticated Windows malware without writing a single line of code. The platform, operating from fudcrypt.net, accepts any Windows executable uploaded by a subscriber and …

NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Institute of Standards and Technology (NIST) has officially updated how it processes vulnerabilities in the National Vulnerability Database (NVD). According to an April 15, 2026 announcement, NIST is abandoning its comprehensive analysis approach in favor of a targeted, …

Google Uses Gemini AI to Stop Malicious Ads From Threat Actors – 8.3 billion ads Blocked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are increasingly leveraging generative AI to launch sophisticated advertising scams at an unprecedented scale. In response, Google has integrated its advanced Gemini AI models into its security infrastructure to neutralize these threats actively. According to Google’s newly released …

Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Flowise and multiple AI frameworks has been discovered by OX Security, exposing millions of users to remote code execution (RCE). The flaw stems from the Model Context Protocol (MCP), a widely used communication standard for AI …

Vercel Confirms Data Breach — Hackers Claim Access to Internal Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vercel has disclosed a significant security incident after threat actors gained unauthorized access to internal systems, with a hacker group reportedly attempting to sell stolen data for $2 million on underground forums. Vercel, one of the most widely used frontend …

Microsoft Teams Right-Click Paste Broken Following Edge Browser Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A confirmed bug in Microsoft Teams desktop client version 26072.519.4556.7438 is disabling the right-click paste option for users on Windows and macOS, with Microsoft attributing the root cause to a code regression introduced in a recent Microsoft Edge browser update. …

OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has officially launched the expanded phase of its Trusted Access for Cyber program. Granting select organizations access to its specialized GPT-5.4-Cyber model to strengthen digital defenses across critical infrastructure, financial services, and open-source security communities. The program operates on a tiered trust model …