Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tax season brings a reliable wave of phishing attacks, but 2026 has already shown a bigger and more organized push than in previous years. Cybercriminals are actively impersonating the Internal …

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware named DeepLoad is targeting enterprise environments, turning a single user action into persistent, credential-stealing access that survives reboots and outlasts standard cleanup efforts. What sets this …

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, …

GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic. Unlike …

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Notepad++ has officially released version 8.9.3, delivering critical security patches, structural performance enhancements, and resolutions for persistent crash issues. This update finalizes the text editor’s transition to a highly optimized …

Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has targeted Axios, one of the most heavily adopted HTTP clients within the JavaScript ecosystem, by introducing a malicious transitive dependency into the official npm …

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s Claude AI successfully discovered zero-day Remote Code Execution (RCE) flaws in both Vim and GNU Emacs. The discoveries highlight a massive paradigm shift in bug hunting, demonstrating that AI …

Exposed Server Reveals TheGentlemen Ransomware Toolkit, Victim Credentials, and Ngrok Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A misconfigured server hosted on a Russian bulletproof hosting provider has exposed the complete operational toolkit of a TheGentlemen ransomware affiliate, including harvested victim credentials and plaintext authentication tokens used …

North Korean IT Worker Allegedly Used Stolen Identity and AI Resume in Job Application Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected North Korean operative tried to sneak into a remote job at a cybersecurity firm by using a stolen identity, a fake AI-generated resume, and a VoIP phone number. …