Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this …

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands …

Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, …

Email-Borne Worm Surge Drives New Threat Wave Across Industrial Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global wave of email-borne worms hit industrial control systems (ICS) in the fourth quarter of 2025, marking one of the most concerning threat shifts seen across operational technology (OT) …

Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the marimo Python notebook platform is now being actively used by attackers to deploy a blockchain-powered backdoor on developer systems. The flaw, tracked as CVE-2026-39987, allows …

Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Brazilian cybersecurity researcher has exposed a sophisticated, large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold through a Chinese marketplace, devices engineered from the ground …

Anthropic Releases Claude Opus 4.7 with Automated Real-Time Cybersecurity Safeguards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has launched Claude Opus 4.7, its latest flagship model, combining improved coding and vision capabilities with automated real-time safeguards to detect and block high-risk cybersecurity requests. The release is …

Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A relatively unknown ransomware group called Payouts King has emerged as a serious cybersecurity threat, carrying the torch of the now-defunct BlackBasta operation. Since its appearance in April 2025, the …

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vulnerability, …