Compromised Namastex npm Packages Deliver TeamPCP-Style CanisterWorm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious supply chain threat has surfaced in the npm ecosystem. Malicious versions of packages belonging to Namastex.ai have been found carrying CanisterWorm malware, a self-propagating backdoor that mirrors the …

Massive SIM Farm-as-a-Service Network Exposes 87 Control Panels Across 17 Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global investigation has uncovered an industrial-scale mobile proxy ecosystem powered by a shared control platform called ProxySmart, with 87 exposed control panels spanning 17 countries and at least 94 …

Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a …

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary …

Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. …

Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the …

Unauthorized Group Gains Access to Anthropic’s Exclusive Cyber Tool Mythos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of unauthorized users has reportedly breached access controls surrounding Claude Mythos Preview, Anthropic’s powerful and closely guarded AI-driven cybersecurity tool, raising serious concerns about third-party vendor security and …

BreachLock Named Representative Vendor in the 2026 Gartner Market Guide for Adversarial Exposure Validation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, United States, April 21st, 2026, CyberNewswire BreachLock, a global leader in offensive security, today announced it has been named a representative vendor in the 2026 Gartner Market Guide for …

The Ungoverned Workforce: Cybersecurity Insiders Finds 92% Lack Visibility Into AI Identities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Washington D.C., USA, April 21st, 2026, CyberNewswire Cybersecurity Insiders, in collaboration with Saviynt, has released new research indicating that AI identities are increasingly operating within core enterprise systems, often without …

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role …