WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been disclosed in Smart Slider 3, one of the most widely used WordPress slider builder plugins. With over 800,000 active installations, this vulnerability leaves a massive …

EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerous phishing toolkit has entered the cybercrime scene. In early 2026, a Phishing-as-a-Service platform called EvilTokens began circulating in underground cybercrime communities, offering criminals a ready-to-use kit …

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Users routinely trust AI assistants with highly sensitive information, including medical records, financial documents, and proprietary business code. Check Point Research recently disclosed a critical vulnerability in ChatGPT’s architecture that …

Apple New macOS Tahoe Feature Warns Users on ClickFix Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has introduced a new security mechanism in the macOS Tahoe 26.4 release candidate to protect users against social engineering campaigns known as ClickFix attacks. Discovered by users testing the …

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical vulnerability affecting Citrix NetScaler products. Identified as CVE-2026-3055, this security flaw has been officially added …

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tax season brings a reliable wave of phishing attacks, but 2026 has already shown a bigger and more organized push than in previous years. Cybercriminals are actively impersonating the Internal …

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware named DeepLoad is targeting enterprise environments, turning a single user action into persistent, credential-stealing access that survives reboots and outlasts standard cleanup efforts. What sets this …

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, …

GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic. Unlike …

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Notepad++ has officially released version 8.9.3, delivering critical security patches, structural performance enhancements, and resolutions for persistent crash issues. This update finalizes the text editor’s transition to a highly optimized …