New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of supply chain attacks is hitting the npm ecosystem through a self-propagating malware campaign known as CanisterWorm. The threat, linked to a group tracked as “TeamPCP,” compromises …

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These security flaws, …

Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, …

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, identified as KB5085516, addressing a critical sign-in bug introduced by the March 2026 Patch Tuesday release. …

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the …

AstraZeneca Data Breach – LAPSUS$ Group Allegedly Claims Access to Internal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective LAPSUS$ has resurfaced, allegedly claiming responsibility for a significant data breach involving the multinational pharmaceutical and biotechnology company AstraZeneca. The threat actors are currently attempting to …

Malicious Script Injection in Trivy Compromise Enables Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Script Injection in Trivy Compromise A sophisticated supply chain attack targeting the official Trivy GitHub Action (aquasecurity/trivy-action) has compromised continuous integration and continuous deployment (CI/CD) pipelines globally. Disclosed in …

FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FBI, CISA Warn Russian Hackers The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread phishing …

Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel …

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services …