Microsoft SharePoint Server Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 Microsoft has disclosed a critical security vulnerability in SharePoint Server that could allow authenticated attackers to execute arbitrary code remotely across multiple versions of the platform. Tracked as CVE-2026-45659 and released on May 21, 2026, the flaw …

Windows Server 2016 Domain Controller May Fail with 15-Character Hostname

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 Windows administrators are facing a disruptive bug in Windows Server 2016 following Microsoft’s May 12, 2026, security update KB5087537. The update introduced a critical flaw that caused domain controller discovery to completely fail on servers configured with …

EU Finalizes Record DMA Fine Against Google Over Search Self-Preferencing Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 The European Union is on the verge of issuing its largest-ever penalty under the Digital Markets Act, targeting Alphabet’s Google for allegedly manipulating search results to favor its own services over competitors, a move set to further …

Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. Rather than relying on traditional SMS messages that carriers can easily flag and block, threat actors are now using …

Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak site with a high-profile target and has since expanded operations …

PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 PuTTY 0.84 has been released with fixes for multiple minor security flaws, including issues that could trigger SSH key exchange crashes and a Telnet prompt spoofing weakness. While these vulnerabilities are considered low severity, they highlight how …

New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory …

Anthropic’s Restricted Claude Mythos Moves Toward Public Release via Claude Code and Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 26, 2026 Anthropic appears to be loosening its grip on Claude Mythos, the company’s most powerful and previously restricted AI model, with new signals pointing to a commercially versioned release under the name Mythos 1 (claude-mythos-1-preview), integrated directly into …

InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making it harder for security software to detect. InvisibleFerret, an information-stealing malware tied to the threat actor known as Void Dokkaebi (also tracked …

Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 25, 2026 A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous technique to hijack Windows systems without alerting anyone on the network. The group modifies a core Windows file called termsrv.dll to unlock …