UAT-8302 Uses Custom Malware and Open-Source Tools to Steal Data From Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A sophisticated China-linked hacker group known as UAT-8302 has been quietly targeting government agencies across South America and southeastern Europe, using a mix of custom malware and …

WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local attackers to escalate their …

Critical Redis Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to …

Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 VM2 has been hit by 11 critical vulnerabilities, putting countless applications that rely on it at risk of executing untrusted code. Affecting all versions up to 3.11.1, …

New Phishing Attack Weaponizing Event Invitations to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign has been quietly targeting organizations across the United States, using fake event invitations as bait. Rather than sending a suspicious attachment or an obvious scam link, …

New Salat Malware Uses QUIC and WebSocket Channels for Stealthy Remote Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A newly identified malware called Salat is raising serious alarms across the cybersecurity community for its sophisticated design and surprisingly wide range of capabilities. Built using the …

New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A new and highly organized fraud network called FEMITBOT has emerged, exploiting Telegram’s Mini App feature to run large-scale cryptocurrency scams and push malicious Android software onto …

Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A dark web platform calling itself Darkhub has surfaced on the Tor network, openly advertising hacking-for-hire services to anyone willing to pay. The platform presents itself as …

CloudZ RAT Abuses Microsoft Phone Link to Steal SMS OTPs and Mobile Notifications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A newly discovered threat is turning a built-in Microsoft feature into a powerful spying tool. Security researchers have found a remote access tool called CloudZ that works …