Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat, carrying the torch of the now-defunct BlackBasta operation. Since its appearance in April 2025, the group has quietly carried out targeted attacks while remaining largely …

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vulnerability, tracked as CVE-2026-34197, to its Known Exploited Vulnerabilities (KEV) catalog. …

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from public GitHub repositories against real enterprise targets. On April 2, 2026, a security researcher operating under the …

Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering repeated reboot loops after installation. Released on April 14, 2026, …

Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates. Discovered and reported …

One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve …

SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified two-component Remote Access Trojan (RAT) toolkit built in Rust, dubbed SpankRAT, is being used by threat actors to abuse legitimate Windows processes, bypass reputation-based security controls, and maintain persistent access to compromised environments while largely evading detection …

Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, has left a significant number of users unable to properly …

Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two American nationals have been sentenced to federal prison for operating a sophisticated “laptop farm” scheme. The operation successfully infiltrated over 100 U.S. companies, generating more than $5 million in illicit revenue to fund the Democratic People’s Republic of Korea …

New UAC-0247 Campaign Steals Browser and WhatsApp Data From Hospitals and Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat cluster tracked as UAC-0247 has been running an active campaign since early 2026, targeting local governments and municipal healthcare institutions across Ukraine, including clinical hospitals and emergency ambulance services. The attackers are not only stealing sensitive data from …