Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A newly disclosed critical vulnerability in Plesk, tracked as CVE-2026-44962, is raising serious security concerns after researchers confirmed it can allow authenticated users to execute arbitrary operating …

Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 Iran-linked hackers have launched a sweeping campaign of digital destruction across the United States and the Middle East, wiping IT systems, erasing backups, and dismantling recovery infrastructure …

New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. Using a combination of fake browser …

Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a service disruption affecting users attempting to set up multi-factor authentication (MFA) or access the self-service sign-in portal at mysignins.microsoft.com. The issue was officially acknowledged by …

Microsoft Tightens Entra ID Password Resets With New Authentication Change

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 Microsoft has announced a significant security update to its Entra ID Self-Service Password Reset (SSPR) feature, introducing stricter authentication requirements designed to reduce identity-based attacks. The update …

Famous Chollima Hackers Target PHP Developers Using Compromised Packagist Package

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A well-known North Korean threat actor has been caught hiding malware inside a legitimate PHP package available through Packagist, the main package repository for PHP projects. The …

Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A new wave of phishing attacks is targeting users of Signal, the encrypted messaging app trusted by journalists, activists, and privacy-conscious individuals worldwide. Hackers are impersonating Signal’s …

Microsoft Clarifies It Won’t Sue Security Researchers Amid Nightmare-Eclipse Controversy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has clarified its stance, reducing perceived legal threats and reaffirming its commitment to coordinated vulnerability disclosure, following significant backlash from the security research community. In a carefully worded statement released in …

Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A critical flaw in Meta’s AI-powered account recovery tool on Instagram allowed attackers to hijack high-value accounts by tricking the chatbot into forwarding password reset codes with …

Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 The critical Windows Netlogon remote code execution (RCE) vulnerability tracked as CVE-2026-41089 is now under active exploitation in the wild, significantly raising the risk profile for unpatched …