Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially rolled out its latest security intelligence update for Microsoft Defender Antivirus, delivering crucial protections for Windows 11, Windows 10, and Windows Server installation images. This vital release ensures that Microsoft’s built-in antimalware solutions are fully equipped to identify …

Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware campaign is putting organizations on high alert. A financially motivated threat group known as Storm-1175 has been running fast-paced attacks targeting vulnerable, internet-facing systems — and deploying the Medusa ransomware as the final blow. What makes this …

50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in the popular WordPress plugin “Ninja Forms – File Upload” has left approximately 50,000 websites vulnerable to complete takeover. Tracked as CVE-2026-0740, this flaw boasts a maximum CVSS severity score of 9.8, making it a severe …

Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families — Vidar on Windows and AMOS on macOS. The operation is still live, with new …

Researcher Released Windows Defender 0-Day Exploit Code, Allowing Attackers to Gain Full Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher operating under the alias Chaotic Eclipse (@ChaoticEclipse0) has publicly dropped a working zero-day local privilege escalation (LPE) exploit for Windows, dubbed BlueHammer, along with full proof-of-concept (PoC) source code on GitHub. The disclosure was confirmed by vulnerability researcher Will Dormann, who …

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-35616, a critical improper access control vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, mandating federal agencies to remediate by April …

Trojanized PyPI AI Proxy Uses Stolen Claude Prompt to Exfiltrates Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Python package has been discovered on PyPI that disguises itself as a privacy-focused AI inference tool while quietly stealing sensitive user data in the background. Named hermes-px, the package marketed itself as a “Secure AI Inference Proxy” that routes …

Hackers Drain $286 Million From Drift Protocol in Suspected North Korea-Linked Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The largest decentralized perpetual futures exchange on the Solana blockchain — became the target of a massive and well-orchestrated theft on April 1, 2026, Drift Protocol. Unknown attackers managed to drain $286 million in digital assets from the platform’s core …

New GitHub Actions Attack Chain Uses Fake CI Updates to Exfiltrate Secrets and Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new attack campaign is actively targeting open-source repositories on GitHub by carefully disguising malicious code as completely routine CI build configuration updates. The campaign, prt-scan exploits a widely misused GitHub Actions workflow trigger to steal sensitive tokens, credentials, and …

DPRK Cyber Program Uses Modular Malware Strategy to Evade Attribution and Survive Takedowns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea’s cyber program has fundamentally shifted how it builds and deploys malware. Rather than relying on one all-purpose hacking tool, the regime has assembled a fragmented ecosystem of purpose-built malware families, each aligned to a specific mission. This shift …