Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 A dangerous infostealer malware called LofyStealer is actively targeting Minecraft players by disguising itself as a game cheat tool named “Slinky.” The malware runs a two-stage attack …

New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware …

New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group …

cPanel Warns of Critical Authentication Flaw – Emergency Patch Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple …

New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 BlobPhish Browser-Based Phishing Attack A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft …

Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub’s internal git infrastructure that could have allowed any authenticated user to compromise backend servers, access millions of private …

Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Microsoft has officially acknowledged a known issue in its April 2026 Windows 11 cumulative update: Remote Desktop Protocol (RDP) security warning dialogs may render incorrectly on certain …

WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 WhatsApp is currently developing an independent cloud backup system designed to give users more direct control over their chat histories. This upcoming feature will allow users to …

New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 A critical zero-click authentication coercion vulnerability, tracked as CVE-2026-32202, stemming from an incomplete patch for a Windows Shell security feature bypass actively weaponized by the Russian APT28 threat …