CERT-EU Confirms Trivy Supply Chain Attack Led to European Commission AWS Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The European Commission’s primary web platform, “europa.eu,” recently suffered a severe data breach stemming from a supply-chain compromise involving the popular open-source vulnerability scanner, Trivy. On April 3, 2026, CERT-EU published an official advisory detailing how a threat actor known …

North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked threat group has successfully hijacked one of the most widely used JavaScript libraries on the internet, injecting malware into millions of potential development environments. On March 31, 2026, attackers gained access to the Axios Node Package Manager …

North Korea-Related Campaign Abuses GitHub as C2 in New LNK Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified campaign linked to North Korean state-sponsored threat actors is using Windows shortcut files, known as LNK files, to launch targeted phishing attacks against organizations in South Korea. What makes this campaign alarming is how attackers conceal their …

20 Best Application Performance Monitoring Tools in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Applications’ performance and availability are monitored, measured, and optimized as part of the practice known as application performance monitoring (APM). Using APM tools and methodologies, organizations may diagnose issues that impair the user experience, discover performance bottlenecks, and gain visibility …

Best VPN For Linux In 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linux users are known for prioritizing privacy, control, and performance — and in 2026, choosing the best VPN for Linux has become more important than ever. While Linux offers stronger security compared to other operating systems, it still doesn’t protect against ISP …

Adobe Breach – Threat Actor Allegedly Claims Leak of 13 Million Support Tickets and Employee Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor identified as “Mr. Raccoon” has allegedly breached Adobe, claiming to have exfiltrated a massive trove of sensitive data, including 13 million support tickets containing personal information, 15,000 employee records, all HackerOne bug bounty submissions, and a range …

How Elite SOCs Cut Escalation Rates by Arming Tier 1 With Better Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elite SOCs Reduce Escalations With Better Threat Intelligence In a mature Security Operations Center, escalation is supposed to work like a scalpel, precise, intentional, and reserved for alerts that genuinely demand deeper expertise. But across many teams today, it has …

Hackers Clone CERT-UA Site to Trick Victims Into Installing Go-Based RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat group recently set up a convincing fake version of Ukraine’s official cybersecurity authority website to trick targets into downloading a dangerous remote access tool. The campaign, now tracked under the identifier UAC-0255, relied on a mix of phishing …

Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor’s EDR Solutions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Qilin ransomware group is deploying a sophisticated, multi-stage infection chain via a malicious msimg32.dll that can disable over 300 endpoint detection and response (EDR) drivers from virtually every major security vendor. As organizations increasingly rely on EDR solutions, which offer …

OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review before upgrading. The most notable security fix targets a shell injection vulnerability in the …