TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. …

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 …

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machines …

Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8, …

84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, …

Google Warns of Hackers Using AI to Create Working Zero-Day Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Threat Intelligence Group recently published an alarming report detailing the rapid industrialization of generative artificial intelligence in adversarial workflows. The most significant finding reveals that a cybercriminal syndicate successfully …

Hackers Use PlugX-Like DLL Sideloading Chain in Fake Claude Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 Cybercriminals are getting creative with how they lure victims into downloading malware, and a new campaign involving a fake version of Anthropic’s Claude AI assistant is raising …

Hackers Use Fake DeepSeek TUI GitHub Repositories to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 Hackers are once again targeting developers and AI enthusiasts by impersonating popular open-source tools on GitHub. This time, the target is DeepSeek TUI, a legitimate terminal-based intelligent …

ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The infamous hacking group ShinyHunters has struck again, this time targeting Instructure, the company behind Canvas Learning Management System (LMS). In early May 2026, Instructure confirmed unauthorized activity on its …