Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage …

Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 Multiple vulnerabilities in the CODESYS Control runtime, one of the world’s most widely adopted software-based programmable logic controller (Soft PLC) platforms. According to Nozomi Networks Labs researchers, …

Top 10 Best NDR (Network Detection and Response) Solutions in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Best NDR Solutions In the modern enterprise, the network is the ultimate source of ground truth. As organizations accelerate their digital transformation and adopt complex, cloud-native security architectures, the traditional …

73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks …

Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued …

New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented …

CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 25, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly …

Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 25, 2026 Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI …

Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and …