CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has officially added a critical vulnerability affecting Aquasecurity’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-33634, this alarming security flaw poses a severe risk to software development pipelines. By exploiting this vulnerability, threat actors can …

FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran-linked hackers have claimed responsibility for breaching FBI Director Kash Patel’s personal Gmail inbox, leaking photographs, documents, and email correspondence online. The hacker group Handala Hack Team announced the breach on their website, declaring that Patel “will now find his …

New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japan’s tax season has become a hunting ground for a well-organized threat actor known as Silver Fox. As Japanese companies enter their annual cycle of tax filing, salary reviews, and personnel changes, this group is taking full advantage of the …

Hackers Deploy BRUSHWORM and BRUSHLOGGER Against South Asian Financial Firm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A South Asian financial institution has become the latest target of a focused cyberattack involving two custom-built malware tools — BRUSHWORM, a modular backdoor, and BRUSHLOGGER, a keylogger disguised as a trusted system file. The attack combined file theft, persistent …

Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly coordinated cyberespionage campaign has been uncovered targeting a government organization in Southeast Asia, with threat actors deploying a mix of USB-propagated malware, remote access trojans (RATs), and data stealers to secure long-term access to sensitive government systems. The …

Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks is putting financial institutions on high alert, as threat actors ramp up the use of PXA Stealer — a powerful information-stealing malware — against organizations worldwide. The surge follows law enforcement’s successful dismantling of major …

Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The official Telnyx Python SDK on PyPI was compromised this morning as part of an escalating, weeks-long supply chain campaign orchestrated by the threat actor group TeamPCP. Malicious versions 4.87.1 and 4.87.2 of the telnyx package were uploaded to PyPI …

Red Hat Warns of Malware Code Embedded in Popular Linux Tool Allow Unauthorized Access to Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat has issued a critical security warning regarding malicious code discovered in recent versions of the “xz” compression tools and libraries. Tracked as CVE-2024-3094, this highly sophisticated supply chain compromise could allow threat actors to bypass authentication and gain …

Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloud Software Group has issued a critical security bulletin detailing two newly discovered vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances. These flaws, tracked as CVE-2026-3055 and CVE-2026-4368, could allow remote attackers to leak sensitive information or cause user …

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new macOS malware that was undocumented previously, is quietly tricking users through fake Cloudflare human verification pages. Called Infiniti Stealer, this threat uses a well-known social engineering trick called ClickFix to convince Mac users into running dangerous commands directly …