Hackers Deploy Modular RAT With Credential Theft and Screenshot Capture Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A newly identified malware campaign is targeting senior executives and government investigators across Southeast Asia, using a modular Remote Access Trojan capable of stealing credentials, capturing screenshots, and maintaining deep persistence on infected systems. The operation, dubbed …

Škoda Security Incident Exposes Customers Data From Online Shop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Škoda Auto has disclosed a significant IT security incident affecting its official online shop, revealing that unauthorized individuals exploited a vulnerability in the platform’s standard shop software to gain temporary unauthorized access to customer data. During routine …

Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A dangerous new infostealer campaign is targeting some of the most sensitive data people store on their computers. Disguised as a legitimate installer for OpenClaw, a popular open-source personal AI assistant, the malware silently takes over systems …

New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A newly discovered malware called ZiChatBot has been found quietly using the REST APIs of a legitimate team chat application called Zulip to receive and carry out commands from its operators. This approach is unusual because the …

Trellix Breach – RansomHouse Claims Access to Parts of Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Trellix, the global cybersecurity firm formed from the merger of McAfee Enterprise and FireEye, has confirmed unauthorized access to a portion of its source code repository, with the RansomHouse ransomware group formally claiming responsibility for the attack. …

Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline …

Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Spring Cloud Config provides crucial server-side and client-side support for externalized configuration in distributed systems. Recently, the Spring development team disclosed four security vulnerabilities impacting the Spring Cloud Config Server. These flaws range from medium to critical …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the …