Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenSSL has released a broad April 2026 security update that fixes seven vulnerabilities across supported branches, led by CVE-2026-31790, a moderate-severity flaw in RSA KEM RSASVE encapsulation that can expose …

FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Justice Department and the FBI have successfully dismantled a massive cyberespionage network in a court-authorized takedown dubbed “Operation Masquerade.” Announced on April 7, 2026, the technical operation neutralized …

CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability chain in the Common Unix Printing System (CUPS) that allows unauthenticated remote attackers to execute arbitrary malicious code with root system privileges. Security researcher Asim Viladi Oglu …

Fiber Optic Cables Turned Into Hidden Microphones to Secretly Spy on Your Conversations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at NDSS 2026 demonstrate a covert acoustic eavesdropping attack that transforms standard FTTH telecom fiber cables into passive, undetectable listening devices invisible to RF scanners and immune to ultrasonic …

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus …

Hackers Exploit Kubernetes Misconfigurations to Move From Containers to Cloud Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kubernetes has become one of the most widely used platforms for managing containerized applications in enterprise environments. But as its adoption has grown, so has the attention it draws from …

Hackers Use Fake Gemini npm Package to Steal Tokens From Claude, Cursor, and Other AI Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new supply chain attack has surfaced targeting software developers who work with AI coding tools. On March 20, 2026, a threat actor published a malicious npm package named gemini-ai-checker under the …

Hackers Exploit Next.js React2Shell Flaw to Steal Credentials From 766 Hosts in 24 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous cyberattack campaign is actively hitting web applications across the internet at a frightening speed. Hackers are exploiting a critical security flaw called React2Shell, targeting websites built on the …

Hackers Use ClickFix Lure to Drop Node.js-Based Windows RAT With Tor-Powered C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of cyberattacks is targeting Windows users through a deceptive social engineering technique called ClickFix. Attackers use a fake browser verification page to trick users into running a …