North Korean Hackers Weaponize Git Hooks to Deploy Cross-Platform Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 North Korean hackers have found a new way to hide malware inside the tools that software developers rely on every single day. Instead of sending phishing emails or planting fake links, they are now burying malicious code …

Malicious Chrome MV3 Extension Impersonates TronLink to Steal Crypto Wallet Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fake Chrome browser extension pretending to be the popular TronLink crypto wallet has been caught stealing sensitive wallet credentials from unsuspecting users. The malicious extension operates silently in the background, harvesting mnemonic phrases, private keys, and …

MistralAI PyPI Package Compromised to Inject Malicious Code – Microsoft Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A popular AI development library has been turned into a weapon. The mistralai PyPI package, version 2.4.6, was found to contain malicious code secretly injected by attackers, putting developers and organizations worldwide at serious risk. The compromise …

Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Researchers have exposed a catastrophic vulnerability hiding inside the “Claude in Chrome” extension. By weaponizing an otherwise harmless, zero-permission extension, invisible attackers can completely hijack the trusted AI assistant. Transform it into a malicious puppet that silently …

Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A serious cluster of vulnerabilities has been uncovered in PHP’s core string processing and ext-soap components, putting numerous web servers at immediate risk of total takeover. While the SOAP extension has a notorious history of memory corruption …

Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers …

TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. In May 2026, a malicious version of the Checkmarx Jenkins …

PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely …

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machines in under 5 minutes by exploiting a crucial gap between …

Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8, this critical flaw has essentially handed the keys to the …