North Korean IT Worker Unmasked After Refusing to Insult Kim Jong Un in Job Interview

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A viral video circulating in cybersecurity and crypto circles has exposed a novel and surprisingly simple technique for unmasking North Korean state-sponsored IT workers attempting to infiltrate Western organizations: asking …

Google’s Bug Bounty Program Hits All-Time High With $17 Million in 2025 Payouts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary in 2025 by breaking every payout record in its history. The tech giant awarded a staggering $17 million to external security …

Apache Traffic Server Vulnerabilities Let Attackers Trigger DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has released emergency security updates to address two severe vulnerabilities in the Apache Traffic Server (ATS). ATS operates as a high-performance web proxy cache that improves …

Critical Dgraph Database Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A maximum-severity vulnerability in Dgraph, a popular open-source graph database. Tracked as CVE-2026-34976, this critical flaw carries a perfect CVSS score of 10.0. It allows unauthenticated remote attackers to bypass …

Hackers Use Poisoned Axios Package and Phantom Dependency to Spread Cross-Platform Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

One of the most widely used JavaScript libraries in the world was turned into a weapon on March 30, 2026, when attackers poisoned the Axios npm package and silently deployed …

Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique, exposing hundreds of thousands …

Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate users into downloading …

METATRON – Open-Source AI Penetration Testing Assistant Brings Local LLM Analysis to Linux

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source penetration testing framework called METATRON is gaining attention in the security research community for its fully offline, AI-driven approach to vulnerability assessment. Built for Parrot OS and …

36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi …