Hackers Hide Malware Payloads Inside Nested macOS-Like Folders to Evade Scanning

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are quietly hiding Windows malware inside nested folders that imitate macOS system paths, making dangerous payloads look like harmless archives to the untrained eye. By burying their tools several layers deep, they aim to slip past automated scanning and …

Splunk Patches Multiple Vulnerabilities that Enable DOS Attacks and Expose Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, …

CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks. The flaw, tracked as CVE-2026-34926, affects …

FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA). Kali365 is being distributed …

Hackers Can Weaponize Lenovo Driver to Terminate EDR Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Hackers can weaponize a legitimately signed Lenovo driver to terminate security processes, highlighting a dangerous Bring Your Own Vulnerable Driver (BYOVD) attack vector that can bypass endpoint protection controls. Security researcher Jehad Abudagga has analyzed a Lenovo …

Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of developers. On May 19, npm invalidated every granular access token with write access that bypasses two-factor authentication, forcing maintainers to …

Discord Announces End-to-End Encryption by Default for Video and Voice Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Discord has officially rolled out end-to-end encryption (E2EE) for all voice and video communications across its platform, marking a major milestone in secure real-time communication. The feature, now enabled by default as of March 2026, applies to …

Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A sweeping automated supply chain attack codenamed “Megalodon” struck GitHub on May 18, 2026, injecting malicious CI/CD backdoors into over 5,500 repositories in less than six hours, marking one of the most aggressive GitHub Actions poisoning campaigns …

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past …

Hackers Use Fake Microsoft Teams Downloads to Deploy ValleyRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have been caught running a deceptive campaign that uses fake Microsoft Teams download websites to trick users into installing ValleyRAT, a remote access trojan capable of stealing data, logging keystrokes, and taking remote control of infected machines. The campaign, …