ROADtools Misused in Cloud Attacks to Steal Tokens and Bypass MFA Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 A well-known open-source security framework called ROADtools has been turned against the organizations it was originally built to protect. Once a legitimate red-teaming tool, attackers are now …

Apple’s New Anti-Snatching Feature Will Auto-Lock iPhones When Stolen From Your Hand

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 Apple is reportedly developing a new iPhone security feature designed to automatically lock the device the moment it detects a theft-in-progress, a significant upgrade to the company’s …

Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day. By abusing popular platforms like npm, PyPI, …

Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 There is a decades-old misconfiguration sitting quietly inside countless business networks, and attackers are still making full use of it. Remote Desktop Protocol, or RDP, allows users …

GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 The anonymous researcher known as Nightmare-Eclipse has been blocked from two major code-hosting platforms in less than a week, as their disruptive public zero-day campaign against Microsoft …

BIND 9 Software Vulnerabilities Exposes Resolvers and Authoritative Servers to Remote Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 A series of newly documented vulnerabilities in ISC BIND 9 has raised significant security concerns for DNS infrastructure operators, with multiple flaws enabling denial-of-service (DoS) attacks, memory …

India’s CERT-In Asks Organizations to Patch Vulnerabilities in Systems Within 12 hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 27, 2026 India’s national computer emergency response agency CERT-In has warned enterprises to patch high-risk vulnerabilities on internet-facing and critical systems within 12 hours of discovery or active exploitation. …

Multiple Angular Language Service Extension Vulnerabilities Enable RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 A set of high-severity vulnerabilities has been identified in the Angular Language Service Visual Studio Code extension (Angular.ng-template), potentially exposing developers to remote code execution (RCE) attacks …