Hackers Hide Backdoor in Trusted WordPress Plugins for 8 Months Before Activating Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of trusted WordPress plugins quietly carried a hidden backdoor for eight full months, and nobody noticed until the damage had already been done. The attack, uncovered in April …

Hackers Create Hidden Mailbox Rules in Microsoft 365 to Intercept Sensitive Business Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a quiet way to sit inside a corporate email account and read everything being sent and received — without the account owner ever knowing. Attackers are now …

Agentic LLM Browsers Expose New Attack Surface for Prompt Injection and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence is changing how people browse the internet. AI-powered browsers no longer just show web pages — they read content, take actions, and complete tasks for the user. These …

FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. Known as Triad Nexus, the group has …

Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft officially released security updates to address a significant vulnerability in Windows BitLocker. Tracked as CVE-2026-27913, this security feature bypass vulnerability was discovered by security researcher Alon Leviev in collaboration …

25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all …

OpenAI Launches GPT-5.4 with Reverse Engineering, Vulnerability and Malware Analysis Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled GPT-5.4-Cyber, a specialized variant of its flagship GPT-5.4 model fine-tuned for advanced defensive cybersecurity workflows, granting vetted security professionals expanded access to capabilities such as binary reverse …

Microsoft SharePoint Server 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day spoofing vulnerability in Microsoft SharePoint Server is being actively exploited in the wild, Microsoft confirmed on April 14, 2026, as part of its monthly security update cycle. …