Cybercriminals Exploit French Fintech Accounts to Move Stolen Money Before Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Organized fraud networks are now using a new method to move stolen money in France. They create fake business accounts on freelancer fintech platforms and use those accounts as mule accounts to launder funds quickly, often before anyone can trace …

Microsoft Warns Jasper Sleet Uses Fake IT Worker Identities to Infiltrate Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked threat group is quietly getting hired by real companies. Jasper Sleet, a threat actor tied to North Korea, has been building fake professional identities and using them to land legitimate remote IT jobs, giving them direct access …

Claude Mythos AI Model Uncovers 271 Zero-Day Vulnerabilities in Firefox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s latest frontier AI model, Claude Mythos Preview, has identified a staggering 271 zero-day vulnerabilities in Mozilla Firefox marking a seismic shift in AI-powered cybersecurity defense. The findings, addressed in Firefox 150, represent the most significant single batch of security …

New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified backdoor called DinDoor is using the legitimate Deno JavaScript runtime and MSI installer files to quietly slip past security defenses and compromise targeted systems. The malware, tracked as a variant of the Tsundere Botnet, relies on trusted, …

Compromised Namastex npm Packages Deliver TeamPCP-Style CanisterWorm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious supply chain threat has surfaced in the npm ecosystem. Malicious versions of packages belonging to Namastex.ai have been found carrying CanisterWorm malware, a self-propagating backdoor that mirrors the attack style of the threat actor known as TeamPCP. The …

Massive SIM Farm-as-a-Service Network Exposes 87 Control Panels Across 17 Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global investigation has uncovered an industrial-scale mobile proxy ecosystem powered by a shared control platform called ProxySmart, with 87 exposed control panels spanning 17 countries and at least 94 physical phone-farm locations enabling large-scale fraud, bot activity, and identity …

Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to …

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability …

Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor …

Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the Microsoft.AspNetCore.DataProtection NuGet package. The out-of-band release was prompted after customers …