Canvas Breach Disrupts Schools & Colleges Nationwide

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that …

New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately. At the time of disclosure, Ivanti …

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 CISA has issued an urgent warning regarding a critical vulnerability in Palo Alto Networks PAN-OS. Tracked as CVE-2026-0300, this severe security flaw was recently added to CISA’s Known Exploited Vulnerabilities catalog on May 6, 2026. The vulnerability …

New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Cisco has issued a critical security advisory regarding a high-severity vulnerability impacting its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO). Tracked formally as CVE-2026-20188 with a CVSS base score of 7.5, this flaw poses a …

Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Hackers are using convincing fake pages for Claude AI to trick users into running malware on their own systems. The campaign, known as “InstallFix” or the Fake Claude Installer threat, marks a sharp shift in how cybercriminals …

Scammers Use Short-Lived VoIP Numbers and Reuse Windows to Defeat Reputation-Based Blocking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Phone-based scams are evolving faster than most security filters can keep up with. Attackers are now leaning heavily on Voice over Internet Protocol (VoIP) numbers that disappear before detection systems can flag them, leaving users exposed and …

UAT-8302 Uses Custom Malware and Open-Source Tools to Steal Data From Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A sophisticated China-linked hacker group known as UAT-8302 has been quietly targeting government agencies across South America and southeastern Europe, using a mix of custom malware and widely available open-source tools to steal sensitive data. The group …

WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local attackers to escalate their privileges to the highest system level, granting them complete control …

Critical Redis Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but …

Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 VM2 has been hit by 11 critical vulnerabilities, putting countless applications that rely on it at risk of executing untrusted code. Affecting all versions up to 3.11.1, each flaw provides attackers with a clear path out of …