Hackers Hijack Hotel Booking Workflows to Scam Guests With Fake Payment Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Travelers across the world are being targeted by a fast-growing fraud scheme that turns their own hotel reservations against them. Cybercriminals are hijacking trusted hotel booking workflows to deliver convincing …

Cisco Source Code and Data Leak Allegedly Claimed by ShinyHunters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal group ShinyHunters has allegedly claimed responsibility for three separate data breaches targeting Cisco Systems, Inc., asserting that over 3 million Salesforce records containing personally identifiable information (PII), …

Windows 11 Emergency Update to Fix Installation Loop Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft just released an emergency out-of-band update to resolve a persistent installation failure affecting Windows 11 users. Released on March 31, 2026, update KB5086672 specifically targets systems running Windows 11 …

North Korean Hackers Compromise Widely Used Axios Package to Infect Windows, macOS, and Linux Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major software supply chain attack has struck the JavaScript ecosystem after threat actors slipped a malicious dependency into the widely used axios NPM package. The poisoned releases, axios 1.14.1 …

Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor group known as TeamPCP has been caught backdooring the Telnyx Python SDK on PyPI — a popular cloud communications library with over 700,000 downloads in February alone. …

New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious npm package named undicy-http has surfaced inside the Node.js developer ecosystem, quietly compromising machines of developers who mistakenly install it. The package impersonates undici, the official HTTP client library bundled with …

PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two high-severity vulnerabilities have been discovered in libpng, the widely used reference library for reading and writing PNG images. These flaws allow attackers to trigger process crashes, leak sensitive information, …

XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known information-stealing malware called XLoader has received significant upgrades in its latest versions, making it considerably harder to detect and analyze than before. Originally derived from a malware family …

Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mercor AI has officially confirmed a severe data breach following claims by the notorious Lapsus$ hacking group that they stole 4 terabytes of sensitive company data. The incident, stemming from …