Let’s Encrypt Halts Certificate Issuance After Cross-Signed Root Certificate Incident

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 9, 2026 Let’s Encrypt temporarily suspended all certificate issuance on May 8, 2026, after engineers identified a critical issue involving a cross-signed certificate linking the organization’s Generation X root to its upcoming Generation Y root infrastructure. The incident triggered …

Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 9, 2026 Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft’s Security …

New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new backdoor called PamDOORa has emerged as a serious and growing threat to Linux systems, targeting one of the most trusted components of the operating system to silently steal SSH credentials. The malware was advertised for sale on a …

Hackers Deploy Modular RAT With Credential Theft and Screenshot Capture Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A newly identified malware campaign is targeting senior executives and government investigators across Southeast Asia, using a modular Remote Access Trojan capable of stealing credentials, capturing screenshots, and maintaining deep persistence on infected systems. The operation, dubbed …

Škoda Security Incident Exposes Customers Data From Online Shop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Škoda Auto has disclosed a significant IT security incident affecting its official online shop, revealing that unauthorized individuals exploited a vulnerability in the platform’s standard shop software to gain temporary unauthorized access to customer data. During routine …

Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A dangerous new infostealer campaign is targeting some of the most sensitive data people store on their computers. Disguised as a legitimate installer for OpenClaw, a popular open-source personal AI assistant, the malware silently takes over systems …

New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 A newly discovered malware called ZiChatBot has been found quietly using the REST APIs of a legitimate team chat application called Zulip to receive and carry out commands from its operators. This approach is unusual because the …

Trellix Breach – RansomHouse Claims Access to Parts of Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Trellix, the global cybersecurity firm formed from the merger of McAfee Enterprise and FireEye, has confirmed unauthorized access to a portion of its source code repository, with the RansomHouse ransomware group formally claiming responsibility for the attack. …

Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline …

Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Spring Cloud Config provides crucial server-side and client-side support for externalized configuration in distributed systems. Recently, the Spring development team disclosed four security vulnerabilities impacting the Spring Cloud Config Server. These flaws range from medium to critical …