Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat, carrying the torch of the now-defunct BlackBasta operation. Since its appearance in April 2025, the …

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vulnerability, …

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from public GitHub repositories against real enterprise targets. …

Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering …

Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched …

One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical …

SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified two-component Remote Access Trojan (RAT) toolkit built in Rust, dubbed SpankRAT, is being used by threat actors to abuse legitimate Windows processes, bypass reputation-based security controls, and …

Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, …

Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two American nationals have been sentenced to federal prison for operating a sophisticated “laptop farm” scheme. The operation successfully infiltrated over 100 U.S. companies, generating more than $5 million in …

New UAC-0247 Campaign Steals Browser and WhatsApp Data From Hospitals and Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat cluster tracked as UAC-0247 has been running an active campaign since early 2026, targeting local governments and municipal healthcare institutions across Ukraine, including clinical hospitals and emergency ambulance …