SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified two-component Remote Access Trojan (RAT) toolkit built in Rust, dubbed SpankRAT, is being used by threat actors to abuse legitimate Windows processes, bypass reputation-based security controls, and maintain persistent access to compromised environments while largely evading detection …

Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, has left a significant number of users unable to properly …

Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two American nationals have been sentenced to federal prison for operating a sophisticated “laptop farm” scheme. The operation successfully infiltrated over 100 U.S. companies, generating more than $5 million in illicit revenue to fund the Democratic People’s Republic of Korea …

New UAC-0247 Campaign Steals Browser and WhatsApp Data From Hospitals and Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat cluster tracked as UAC-0247 has been running an active campaign since early 2026, targeting local governments and municipal healthcare institutions across Ukraine, including clinical hospitals and emergency ambulance services. The attackers are not only stealing sensitive data from …

Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued an urgent security advisory warning of multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). According to the official Cisco security advisory published on April 15, 2026, these flaws could allow an …

31 High-Impact Vulnerabilities Exploited in March as Interlock Hits Cisco FMC Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

March 2026 turned out to be one of the more active months for vulnerability exploitation this year. Security researchers tracked 31 high-impact vulnerabilities that were actively used against real-world systems, touching products from more than 20 major vendors including Cisco, …

New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chrome is the most widely used browser in the world, yet a sweeping new analysis reveals it offers users almost no protection against fingerprinting and data leaks that quietly expose their identity to websites and trackers. Published April 14, …

Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been officially disclosed, affecting multiple versions of Enterprise and Cloud platforms. Tracked as CVE-2026-20204, this high-severity flaw carries a CVSS score of 7.1 and poses a significant threat to organizational networks. Discovered and reported by …

1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia’s commercial hosting ecosystem. Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across …

Hackers Abuse Google Discover With AI-Generated Content to Push Malicious Notifications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified threat operation is exploiting one of the most widely used content discovery tools on Android and Chrome devices — Google’s Discovery feed — to deliver malicious push notifications to unsuspecting users across multiple countries. The operation, named Pushpaganda by …