Chinese Silk Typhoon Hacker Extradited to the U.S. from Italy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A Chinese national tied to one of the most damaging state-sponsored hacking campaigns in recent history has been extradited to the United States from Italy. Xu Zewei, 34, a citizen of the People’s Republic of China, landed …

WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 WhatsApp is currently developing an independent cloud backup system designed to give users more direct control over their chat histories. This upcoming feature will allow users to store their backups securely on WhatsApp’s native servers. The update …

New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A critical zero-click authentication coercion vulnerability, tracked as CVE-2026-32202, stemming from an incomplete patch for a Windows Shell security feature bypass actively weaponized by the Russian APT28 threat group. Microsoft confirmed active exploitation of the flaw and released …

New Silver Fox Campaign Uses Fake Tax Audit Alerts and Software Updates to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Silver Fox, a China-based threat group has launched a new wave of attacks targeting businesses and individuals across Asia, using fake tax audit notifications and counterfeit software update alerts to install dangerous malware on victim systems. The …

Chinese-Backed Smishing Services Use OTT Messaging and SMS to Scale Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A wave of large-scale phishing campaigns backed by Chinese-language services is quietly targeting people around the world, using everyday messaging apps to steal personal and financial credentials. These operations have grown well beyond regional limits, making them …

Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the …

Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A new fake document reader app found on the Google Play Store has been silently installing Anatsa, a powerful Android banking trojan, on thousands of user devices. The malicious application surpassed 10,000 downloads before Google removed it, …

AI Coding Agent Powered by Claude Opus 4.6 Deletes Production Database in 9 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Cursor AI coding agent powered by Anthropic’s Claude Opus 4.6 deleted the entire production database and all volume-level backups of PocketOS, a SaaS platform serving car rental businesses nationwide, in a single unauthorized API call on Friday, April 25, …

Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A security vulnerability has been identified in Notepad++, one of the most widely used open-source text editors among developers and IT professionals. The vulnerability CVE-2026-3008, which could allow a remote attacker to crash the application or extract …

ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Home Depot, Tenable, Mayo Clinic, and U.S. state government workers, through a hardcoded …