Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the marimo Python notebook platform is now being actively used by attackers to deploy a blockchain-powered backdoor on developer systems. The flaw, tracked as CVE-2026-39987, allows …

Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Brazilian cybersecurity researcher has exposed a sophisticated, large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold through a Chinese marketplace, devices engineered from the ground …

Anthropic Releases Claude Opus 4.7 with Automated Real-Time Cybersecurity Safeguards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has launched Claude Opus 4.7, its latest flagship model, combining improved coding and vision capabilities with automated real-time safeguards to detect and block high-risk cybersecurity requests. The release is …

Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat, carrying the torch of the now-defunct BlackBasta operation. Since its appearance in April 2025, the …

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vulnerability, …

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from public GitHub repositories against real enterprise targets. …

Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering …

Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched …

One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical …