SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 A new supply chain attack dubbed “mini Shai Hulud” has compromised four SAP-related npm packages by injecting malicious preinstall scripts that silently execute during dependency installation, targeting developer environments and CI/CD pipelines to steal credentials across GitHub, …

Lazarus Hackers Attacking macOS Users With ‘Mach-O Man’ Malware Kit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 Mach-O Man Malware Targets macOS Crypto Executives North Korea’s state-sponsored Lazarus Group has unleashed a newly identified, modular macOS malware kit dubbed “Mach-O Man” a sophisticated, four-stage attack chain targeting fintech executives, crypto developers, and high-value enterprise …

Brinker Introduces a Novel Approach to Deepfake Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 WILMINGTON, Delaware, April 29th, 2026, CyberNewswire Malicious intent-based deepfake detection shifts the focus from purely technical analysis to real-world risk and impact Brinker, recently named “Narrative Intelligence Solution of the Year 2026” by The Cyber Review, today …

Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 A dangerous infostealer malware called LofyStealer is actively targeting Minecraft players by disguising itself as a game cheat tool named “Slinky.” The malware runs a two-stage attack that quietly steals sensitive data from popular web browsers while …

New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files and demands payment for decryption, VECT 2.0 …

New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group behind this activity is BlueNoroff, a financially motivated subgroup known …

cPanel Warns of Critical Authentication Flaw – Emergency Patch Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 29, 2026 Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) …

New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 BlobPhish Browser-Based Phishing Attack A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining …

Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub’s internal git infrastructure that could have allowed any authenticated user to compromise backend servers, access millions of private repositories, and, in the case of GitHub Enterprise Server (GHES), …

Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 28, 2026 Microsoft has officially acknowledged a known issue in its April 2026 Windows 11 cumulative update: Remote Desktop Protocol (RDP) security warning dialogs may render incorrectly on certain system configurations, a significant usability concern given that the warnings …