WantToCry Ransomware Abuses SMB Services to Remotely Encrypt Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A ransomware strain called WantToCry has been targeting businesses by abusing a widely used file-sharing protocol to encrypt files without dropping any malware on the victim’s system. The attacks mark a notable shift in how ransomware operators …

Two U.S. Executives Plead Guilty in India-Based Tech-Support Fraud Schemes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 Two former executives of a U.S.-based call routing and analytics company have pleaded guilty to federal charges for knowingly enabling India-based call centers to defraud thousands of American victims through elaborate tech-support scam operations spanning nearly six …

New GhostTree Attack Causing EDR Products to Hang and Leave Files Unscanned

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A novel evasion technique called GhostTree, which exploits NTFS junctions to create recursive directory loops. Uncovered by Varonis Threat Labs, this method traps Endpoint Detection and Response (EDR) scanners in infinite paths, causing them to hang and …

Claude Code’s Network Sandbox Vulnerability Exposes User Credentials and Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 Anthropic’s Claude Code AI coding assistant harbored a critical network sandbox bypass for over five months, allowing attackers to exfiltrate credentials, source code, and environment variables from developer systems, and the company issued no public advisory for …

Gremlin Stealer Stores C2 URLs and Exfiltration Paths in Encrypted Resource Sections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 21, 2026 A newly analyzed variant of the Gremlin stealer malware has raised alarms by hiding its command-and-control (C2) addresses and data exfiltration paths inside encrypted resource sections of a compiled program. This approach makes the malware harder to …

Hackers Use Fake Income Tax Assessment Pages to Infect Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A new threat campaign is targeting Windows users in India by disguising malicious files as official income tax documents. Researchers have tracked the operation under the name TAX#TRIDENT, and it has shown the ability to pivot across …

Void Botnet Uses Ethereum Smart Contracts for Seizure-Resistant C2 Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A new botnet called Void has emerged on the cybercrime underground, bringing a troubling twist to how attackers manage their operations remotely. Instead of relying on traditional servers that authorities can seize or shut down, Void Botnet …

Trapdoor Android Ad Fraud Operation Uses 455 Malicious Apps to Generate Fake Clicks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A large-scale ad fraud operation called Trapdoor has been discovered targeting Android users through 455 malicious apps, quietly generating fake ad clicks and draining real advertising budgets across the digital ecosystem. At its peak, the operation produced …

DevilNFC Android Malware Uses Kiosk Mode to Trap Victims During NFC Relay Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new Android malware called DevilNFC has emerged, combining NFC relay attacks with a Kiosk Mode trap that locks victims inside a fake banking screen until their card data is stolen. The malware targets customers across Europe and LATAM …

PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Discovered by Aaron Esau of the V12 security team, the flaw allows local attackers to gain root access by exploiting …