New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A newly discovered malware called ZiChatBot has been found quietly using the REST APIs of a legitimate team chat application called Zulip to receive and carry out commands from its operators. This approach is unusual because the …

Trellix Breach – RansomHouse Claims Access to Parts of Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Trellix, the global cybersecurity firm formed from the merger of McAfee Enterprise and FireEye, has confirmed unauthorized access to a portion of its source code repository, with the RansomHouse ransomware group formally claiming responsibility for the attack. …

Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline …

Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Spring Cloud Config provides crucial server-side and client-side support for externalized configuration in distributed systems. Recently, the Spring development team disclosed four security vulnerabilities impacting the Spring Cloud Config Server. These flaws range from medium to critical …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the …

Canvas Breach Disrupts Schools & Colleges Nationwide

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that …

New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately. At the time of disclosure, Ivanti …

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 CISA has issued an urgent warning regarding a critical vulnerability in Palo Alto Networks PAN-OS. Tracked as CVE-2026-0300, this severe security flaw was recently added to CISA’s Known Exploited Vulnerabilities catalog on May 6, 2026. The vulnerability …