Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Brazilian cybersecurity researcher has exposed a sophisticated, large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold through a Chinese marketplace, devices engineered from the ground …

Anthropic Releases Claude Opus 4.7 with Automated Real-Time Cybersecurity Safeguards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has launched Claude Opus 4.7, its latest flagship model, combining improved coding and vision capabilities with automated real-time safeguards to detect and block high-risk cybersecurity requests. The release is …

Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat, carrying the torch of the now-defunct BlackBasta operation. Since its appearance in April 2025, the …

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vulnerability, …

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from public GitHub repositories against real enterprise targets. …

Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering …

Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched …

One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical …

SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified two-component Remote Access Trojan (RAT) toolkit built in Rust, dubbed SpankRAT, is being used by threat actors to abuse legitimate Windows processes, bypass reputation-based security controls, and …

Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, …