New Silver Fox Campaign Uses Fake Tax Audit Alerts and Software Updates to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Silver Fox, a China-based threat group has launched a new wave of attacks targeting businesses and individuals across Asia, using fake tax audit notifications and counterfeit software …

Chinese-Backed Smishing Services Use OTT Messaging and SMS to Scale Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A wave of large-scale phishing campaigns backed by Chinese-language services is quietly targeting people around the world, using everyday messaging apps to steal personal and financial credentials. …

Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, …

AI Coding Agent Powered by Claude Opus 4.6 Deletes Production Database in 9 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Cursor AI coding agent powered by Anthropic’s Claude Opus 4.6 deleted the entire production database and all volume-level backups of PocketOS, a SaaS platform serving car rental businesses nationwide, …

Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A security vulnerability has been identified in Notepad++, one of the most widely used open-source text editors among developers and IT professionals. The vulnerability CVE-2026-3008, which could …

ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Home Depot, Tenable, …

New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A credential-stealing malware named Vidar has quietly emerged as one of the most active threats targeting corporate employees in early 2026. Threat actors are using fake software …

North Korean Hackers Attacking Drug Companies to Deploy Malware Via Weaponized Excel Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 North Korean state-sponsored hackers from the Kimsuky group have launched a targeted campaign against prescription pharmaceutical companies, using a cleverly disguised malware file named White Life Science …

Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage …