Microsoft Details Steps to Mitigate the Axios npm Supply Chain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used JavaScript library called Axios was at the center of a serious supply chain attack that came to light on March 31, 2026. Two updated versions of the Axios npm package — version 1.14.1 and version 0.30.4 — …

Apple Expands iOS 18.7.7 Update to More Devices to Shield Users from DarkSword Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has taken the rare step of expanding the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader set of devices on April 1, 2026, pushing critical backported security patches to millions of users still running iOS 18 who …

Apple Expands iOS 18.7.7 Update to More Devices to Shield Users from DarkSword Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has taken the rare step of expanding the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader set of devices on April 1, 2026, pushing critical backported security patches to millions of users still running iOS 18 who …

New ZAP PTK Add-On Maps Browser-Based Security Findings as Native Alert Into ZAP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OWASP Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new release bridges the critical gap between traditional proxy-level scanning and …

New ZAP PTK Add-On Maps Browser-Based Security Findings as Native Alert Into ZAP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OWASP Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new release bridges the critical gap between traditional proxy-level scanning and …

WhatsApp Warns Users Targeted by Spyware Attack via Weaponized Version of the App

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has officially alerted approximately 200 WhatsApp users, primarily located in Italy, that their devices were compromised by a weaponized, fraudulent version of the messaging application. This malicious software was distributed through social engineering tactics rather than official app stores, …

Cisco Smart Software Manager Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued an urgent security warning regarding a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem) platform. Enterprise organizations widely use this tool to manage their Cisco software licenses locally. Tracked as CVE-2026-20160, the flaw carries a …

Oracle Lays Off 30,000 Employees to Ramp Up Investment in AI Technologies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has executed a massive workforce reduction, eliminating between 20,000 and 30,000 employees globally to free up cash flow for its aggressive artificial intelligence infrastructure investments. The layoffs, representing roughly 18% of its workforce, were communicated abruptly via email, highlighting …

Critical PX4 Autopilot Vulnerability Let Attackers Gain Control Over the Drones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered critical vulnerability in the widely used PX4 Autopilot software could allow malicious actors to take complete control over drone operations. The Cybersecurity and Infrastructure Security Agency (CISA) released an Industrial Control Systems (ICS) advisory on March 31, …

FBI Warns of Chinese Mobile Apps May Expose User Data to Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Millions of Americans use mobile apps daily without thinking much about where their data actually goes. The Federal Bureau of Investigation has stepped forward to address that. On March 31, 2026, the FBI released a Public Service Announcement outlining serious …