Malicious Chrome MV3 Extension Impersonates TronLink to Steal Crypto Wallet Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fake Chrome browser extension pretending to be the popular TronLink crypto wallet has been caught stealing sensitive wallet credentials from unsuspecting users. The malicious extension operates …

MistralAI PyPI Package Compromised to Inject Malicious Code – Microsoft Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A popular AI development library has been turned into a weapon. The mistralai PyPI package, version 2.4.6, was found to contain malicious code secretly injected by attackers, …

Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Researchers have exposed a catastrophic vulnerability hiding inside the “Claude in Chrome” extension. By weaponizing an otherwise harmless, zero-permission extension, invisible attackers can completely hijack the trusted …

Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A serious cluster of vulnerabilities has been uncovered in PHP’s core string processing and ext-soap components, putting numerous web servers at immediate risk of total takeover. While …

TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. …

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 …

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machines …

Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8, …

84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, …