OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review before upgrading. The most notable security fix targets a shell injection vulnerability in the …

Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A seemingly routine procurement email has become the entry point for a sophisticated six-stage malware attack targeting industrial suppliers and procurement teams. The campaign, tracked as NKFZ5966PURCHASE, disguises itself as a Boeing Request for Quotation (RFQ) from a person named …

CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical warning has been issued over a newly discovered zero-day vulnerability in Google Chrome, raising serious concerns for users worldwide. This flaw is actively exploited in the wild, allowing attackers to bypass security protections and execute malicious code, and …

NoVoice on Google Play with 22 Exploits Attacks Millions of Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Android rootkit named NoVoice has been hiding inside over 50 apps on Google Play, compromising more than 2.3 million devices worldwide. Tracked as Operation NoVoice, the malware uses 22 exploits to take full control of a device without …

Microsoft Details Steps to Mitigate the Axios npm Supply Chain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used JavaScript library called Axios was at the center of a serious supply chain attack that came to light on March 31, 2026. Two updated versions of the Axios npm package — version 1.14.1 and version 0.30.4 — …

Apple Expands iOS 18.7.7 Update to More Devices to Shield Users from DarkSword Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has taken the rare step of expanding the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader set of devices on April 1, 2026, pushing critical backported security patches to millions of users still running iOS 18 who …

Apple Expands iOS 18.7.7 Update to More Devices to Shield Users from DarkSword Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has taken the rare step of expanding the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader set of devices on April 1, 2026, pushing critical backported security patches to millions of users still running iOS 18 who …

New ZAP PTK Add-On Maps Browser-Based Security Findings as Native Alert Into ZAP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OWASP Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new release bridges the critical gap between traditional proxy-level scanning and …

New ZAP PTK Add-On Maps Browser-Based Security Findings as Native Alert Into ZAP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OWASP Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new release bridges the critical gap between traditional proxy-level scanning and …

WhatsApp Warns Users Targeted by Spyware Attack via Weaponized Version of the App

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has officially alerted approximately 200 WhatsApp users, primarily located in Italy, that their devices were compromised by a weaponized, fraudulent version of the messaging application. This malicious software was distributed through social engineering tactics rather than official app stores, …