LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on …

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation …

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS …

Operation Dragon Whistle Uses Malicious LNK Files to Target Changzhou University

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A newly uncovered cyber operation has raised concerns among security professionals after a coordinated wave of attacks targeted government institutions in Pakistan. The campaign, now tracked as …

Canadian Man Arrested for Running KimWolf DDoS Botnet Service that Hacked 2 Million Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Canadian and U.S. authorities have arrested and charged a 23‑year‑old Ottawa resident for allegedly operating “KimWolf,” a massive Internet‑of‑Things (IoT) DDoS‑for‑hire botnet that weaponized more than a …

Hackers Hide Malware Payloads Inside Nested macOS-Like Folders to Evade Scanning

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are quietly hiding Windows malware inside nested folders that imitate macOS system paths, making dangerous payloads look like harmless archives to the untrained eye. By burying their tools several …

Splunk Patches Multiple Vulnerabilities that Enable DOS Attacks and Expose Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and …

CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations …

FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access …