Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families — Vidar on Windows and AMOS on macOS. The operation is still live, with new …

Researcher Released Windows Defender 0-Day Exploit Code, Allowing Attackers to Gain Full Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher operating under the alias Chaotic Eclipse (@ChaoticEclipse0) has publicly dropped a working zero-day local privilege escalation (LPE) exploit for Windows, dubbed BlueHammer, along with full proof-of-concept (PoC) source code on GitHub. The disclosure was confirmed by vulnerability researcher Will Dormann, who …

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-35616, a critical improper access control vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, mandating federal agencies to remediate by April …

Trojanized PyPI AI Proxy Uses Stolen Claude Prompt to Exfiltrates Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Python package has been discovered on PyPI that disguises itself as a privacy-focused AI inference tool while quietly stealing sensitive user data in the background. Named hermes-px, the package marketed itself as a “Secure AI Inference Proxy” that routes …

Hackers Drain $286 Million From Drift Protocol in Suspected North Korea-Linked Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The largest decentralized perpetual futures exchange on the Solana blockchain — became the target of a massive and well-orchestrated theft on April 1, 2026, Drift Protocol. Unknown attackers managed to drain $286 million in digital assets from the platform’s core …

New GitHub Actions Attack Chain Uses Fake CI Updates to Exfiltrate Secrets and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new attack campaign is actively targeting open-source repositories on GitHub by carefully disguising malicious code as completely routine CI build configuration updates. The campaign, prt-scan exploits a widely misused GitHub Actions workflow trigger to steal sensitive tokens, credentials, and …

DPRK Cyber Program Uses Modular Malware Strategy to Evade Attribution and Survive Takedowns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea’s cyber program has fundamentally shifted how it builds and deploys malware. Rather than relying on one all-purpose hacking tool, the regime has assembled a fragmented ecosystem of purpose-built malware families, each aligned to a specific mission. This shift …

North Korean IT Worker Unmasked After Refusing to Insult Kim Jong Un in Job Interview

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A viral video circulating in cybersecurity and crypto circles has exposed a novel and surprisingly simple technique for unmasking North Korean state-sponsored IT workers attempting to infiltrate Western organizations: asking them to insult their Supreme Leader. The footage shows a …

Google’s Bug Bounty Program Hits All-Time High With $17 Million in 2025 Payouts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary in 2025 by breaking every payout record in its history. The tech giant awarded a staggering $17 million to external security researchers worldwide, representing a massive 40% surge compared to 2024. …

Apache Traffic Server Vulnerabilities Let Attackers Trigger DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has released emergency security updates to address two severe vulnerabilities in the Apache Traffic Server (ATS). ATS operates as a high-performance web proxy cache that improves network efficiency and handles massive volumes of enterprise web traffic. …