MuddyWater Turns to Russian Malware-as-a-Service in New ChainShell Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian state-backed hacking group MuddyWater has made a decisive operational shift, adopting a Russian-built Malware-as-a-Service platform to power a new campaign against Israeli targets. The operation, built around a previously …

Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified five distinct security flaws in the TP-Link Archer AX53 v1.0 router. Tracked under multiple CVE identifiers, these vulnerabilities impact the router’s core modules, including OpenVPN, dnsmasq, …

CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cpuid-dot-com website, home to widely used system utilities CPU-Z and HWMonitor, is at the center of an active supply chain security incident. Users downloading HWMonitor 1.63 or CPU-Z ZIPs …

Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake developer extension published on the OpenVSX marketplace is silently spreading a known malware strain called GlassWorm to every code editor installed on a developer’s machine. The malicious package …

Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, Texas, United States, April 9th, 2026, CyberNewswire Built by a veteran security team and led by a former Google and Mandiant executive, Mallory delivers intelligence that drives action for …

Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based attackers to gain full administrative control …

DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Remote Access Trojan known as DesckVB has been targeting systems in 2026, using obfuscated JavaScript and a fileless .NET loader to stay hidden from traditional security tools. The …

React Server Components Vulnerability Enables DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been discovered in React Server Components, exposing modern web applications to Denial of Service (DoS) attacks. Tracked as CVE-2026-23869, this flaw allows unauthenticated remote attackers to …

Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive Magecart campaign compromising 99 Magento e-commerce stores using an innovative evasion technique. Discovered on April 7, 2026, the attack relies on invisible Scalable Vector Graphics (SVG) elements to …

Single Line of Code Can jailbreak 11 AI models Including ChatGPT, Claude, and Gemini

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly detailed jailbreak technique known as “sockpuppeting” allows attackers to bypass the safety guardrails of 11 major large language models (LLMs) using a single line of code. Unlike complex …