Void Botnet Uses Ethereum Smart Contracts for Seizure-Resistant C2 Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A new botnet called Void has emerged on the cybercrime underground, bringing a troubling twist to how attackers manage their operations remotely. Instead of relying on traditional servers that authorities can seize or shut down, Void Botnet …

Trapdoor Android Ad Fraud Operation Uses 455 Malicious Apps to Generate Fake Clicks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A large-scale ad fraud operation called Trapdoor has been discovered targeting Android users through 455 malicious apps, quietly generating fake ad clicks and draining real advertising budgets across the digital ecosystem. At its peak, the operation produced …

DevilNFC Android Malware Uses Kiosk Mode to Trap Victims During NFC Relay Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new Android malware called DevilNFC has emerged, combining NFC relay attacks with a Kiosk Mode trap that locks victims inside a fake banking screen until their card data is stolen. The malware targets customers across Europe and LATAM …

PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Discovered by Aaron Esau of the V12 security team, the flaw allows local attackers to gain root access by exploiting …

How to Close the Most Expensive Gap in Your SOC 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 Close Your SOC’s Most Expensive Gap There is a quiet gap inside many SOCs. It sits between the moment Tier 1 says “this should be escalated” and the moment the response team can actually act on it. Too often, …

Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing sensitive data within minutes. The flaw was publicly disclosed on …

New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in some conditions, remote code execution in the NGINX worker process. …

GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in a series of official statements on May 20, 2026. The …

PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly two decades, highlights the long-standing risks associated with memory handling …

ShinyHunters Claims Credit for Cyber-Attack on Online Learning Management System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A recent cyberattack targeting an online Learning Management System (LMS) has been attributed to the notorious cybercriminal group ShinyHunters. The incident caused widespread service disruptions affecting educational institutions and students across the United States, although the platform …