Hackers Used Claude AI to Attack on Water and Drainage Utility Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A new threat intelligence report has revealed that an unknown group of hackers used a commercial AI tool to target the systems of a municipal water and drainage utility in Monterrey, Mexico. The attack, which took place …

New Phishing Attack Weaponizing Event Invitations to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign has been quietly targeting organizations across the United States, using fake event invitations as bait. Rather than sending a suspicious attachment or an obvious scam link, attackers lure victims with what appears to be a legitimate …

New Salat Malware Uses QUIC and WebSocket Channels for Stealthy Remote Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A newly identified malware called Salat is raising serious alarms across the cybersecurity community for its sophisticated design and surprisingly wide range of capabilities. Built using the Go programming language, it operates as a full remote access …

New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 A new and highly organized fraud network called FEMITBOT has emerged, exploiting Telegram’s Mini App feature to run large-scale cryptocurrency scams and push malicious Android software onto users worldwide. The campaign, which came to light in April …

Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A dark web platform calling itself Darkhub has surfaced on the Tor network, openly advertising hacking-for-hire services to anyone willing to pay. The platform presents itself as a one-stop shop for illegal cyber activity, with offerings ranging …

CloudZ RAT Abuses Microsoft Phone Link to Steal SMS OTPs and Mobile Notifications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A newly discovered threat is turning a built-in Microsoft feature into a powerful spying tool. Security researchers have found a remote access tool called CloudZ that works alongside a custom plugin named Pheno to silently intercept SMS …

QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A new and previously undocumented Linux threat has emerged, targeting software developers in a way that could put entire supply chains at risk. Named Quasar Linux, or QLNX, this malware operates as a full-featured remote access trojan …

Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Latvian national operating out of Moscow was sentenced to 102 months in federal prison for his central role in a sprawling Russian ransomware syndicate. Deniss Zolotarjovs, 35, served as a primary extortionist and negotiator for a highly organized cybercriminal …

Argo CD’s ServerSideDiff Vulnerability Enables Kubernetes Secret Extraction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A critical cybersecurity vulnerability has been uncovered in Argo CD, a widely used declarative GitOps continuous delivery tool for Kubernetes environments. Tracked as CVE-2026-43824, this high-severity flaw allows low-privileged users to extract plaintext Kubernetes Secrets directly from …

Salesforce Marketing Cloud Vulnerability Opened Door to Email Data Exposure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A significant set of security vulnerabilities in Salesforce Marketing Cloud (SFMC) could have allowed attackers to read and expose private email data belonging to millions of users across hundreds of organizations. The flaws, now patched, were rooted …