Hackers Leave Credential Stuffing Botnet Wide Open With Full Worker Access and Root Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A live credential stuffing botnet targeting Twitter/X accounts has been found completely exposed to the internet, with no password required to access its control panel, worker server credentials, or real-time …

Codex Hacks Samsung TV to Root by Exploiting World-Writable Driver Interfaces

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s Codex AI model successfully escalated privileges to root on a real Samsung Smart TV by exploiting world-writable kernel driver interfaces — a finding that raises serious questions about how …

CISA Warns of Fortinet SQL Injection Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Fortinet products. On April 13, 2026, the agency added a severe SQL …

Hackers Weaponize Obsidian Shell Commands Plugin to Launch Cross-Platform Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have found a clever way to abuse a trusted productivity tool to deliver malware. By weaponizing Obsidian’s Shell Commands community plugin, attackers are quietly executing malicious code on …

Booking.com Confirms Data Breach — Hackers Accessed Customers’ Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global travel booking giant Booking.com has confirmed a cyberattack in which unauthorized third parties gained access to customers’ personal data, including names, email addresses, phone numbers, and reservation details, raising …

APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT41 is once again pushing its Linux capabilities forward, this time by quietly turning cloud servers into powerful credential theft platforms. The group’s latest Winnti-family backdoor is a zero‑detection ELF …

W3LL Phishing Kit Takedown Hits Global Credential Theft and MFA Bypass Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI Atlanta Field Office, working in a historic joint operation with Indonesian law enforcement, has successfully dismantled a massive global phishing network. The investigation targeted the notorious W3LL phishing …

Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has been silently targeting cryptocurrency users by hiding inside a fake version of Proxifier, a popular proxy software tool. Threat actors set up a GitHub repository …