Hackers Backdoor Telnyx Python SDK on PyPI to Steal Cloud and Dev Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used Python package was quietly turned into a weapon, and most developers who got hit had no idea it happened. On March 27, 2026, a threat actor known as TeamPCP uploaded two malicious versions of the Telnyx Python …

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw was recently found in Open VSX, the extension marketplace used by popular code editors like Cursor and Windsurf, as well as the broader VS Code fork ecosystem. The vulnerability was found inside the platform’s newly introduced …

BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Python-based information stealer known as BlankGrabber has been caught using a deceptive certificate loader trick to hide a multi-stage malware delivery chain. First identified in 2023, this threat has grown more complex over time and keeps targeting everyday users …

Stored XSS Bug in Jira Work Management Could Lead to Full Organization Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular collaboration tool within the Atlassian ecosystem is widely used by organizations to track projects, manage approvals, and manage daily tasks. Recently, security researchers at Snapsec uncovered a critical Stored Cross-Site Scripting (XSS) vulnerability within the platform. By exploiting a …

CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as TeamPCP, operates a self-propagating worm called CanisterWorm that hunts for …

Vim Vulnerability Let Attackers Execute Arbitrary Command Via Weaponized Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been discovered in Vim, one of the most widely used text editors among developers. This vulnerability allows attackers to execute arbitrary operating system commands simply by tricking a user into opening a specially crafted file. Discovered …

Critical Grafana Vulnerabilities Let Attackers Achieve Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Urgent security updates for Grafana version 12.4.2 address two critical vulnerabilities that could allow attackers to achieve full remote code execution (RCE) and execute denial-of-service (DoS) attacks. System administrators utilizing Grafana for data visualization are strongly advised to apply these …

Critical n8n Vulnerability Let Attackers Achieve Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in n8n, a widely used open-source workflow automation platform, exposes host servers to Remote Code Execution (RCE) attacks. Tracked as CVE-2026-33660, this critical vulnerability allows authenticated threat actors to bypass built-in security restrictions, access sensitive data, …

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Databricks is currently investigating an alleged security compromise connected to the massive TeamPCP software supply chain attack after being alerted by threat intelligence researchers. According to International Cyber Digest, Databricks was notified of the potential breach last week. The organization …

Critical Fortinet Forticlient EMS Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-21643, is actively being exploited in the wild. Threat actors have been leveraging this flaw in attacks starting four days ago, despite it not yet appearing …