Hackers Clone CERT-UA Site to Trick Victims Into Installing Go-Based RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat group recently set up a convincing fake version of Ukraine’s official cybersecurity authority website to trick targets into downloading a dangerous remote access tool. The campaign, now tracked …

Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor’s EDR Solutions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Qilin ransomware group is deploying a sophisticated, multi-stage infection chain via a malicious msimg32.dll that can disable over 300 endpoint detection and response (EDR) drivers from virtually every major security …

OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review before upgrading. The most …

Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A seemingly routine procurement email has become the entry point for a sophisticated six-stage malware attack targeting industrial suppliers and procurement teams. The campaign, tracked as NKFZ5966PURCHASE, disguises itself as …

CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical warning has been issued over a newly discovered zero-day vulnerability in Google Chrome, raising serious concerns for users worldwide. This flaw is actively exploited in the wild, allowing …

NoVoice on Google Play with 22 Exploits Attacks Millions of Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Android rootkit named NoVoice has been hiding inside over 50 apps on Google Play, compromising more than 2.3 million devices worldwide. Tracked as Operation NoVoice, the malware uses …

New ZAP PTK Add-On Maps Browser-Based Security Findings as Native Alert Into ZAP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OWASP Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new …