ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Home Depot, Tenable, Mayo Clinic, and U.S. state government workers, through a hardcoded …

New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 A credential-stealing malware named Vidar has quietly emerged as one of the most active threats targeting corporate employees in early 2026. Threat actors are using fake software downloads promoted through YouTube videos to trick workers into installing …

North Korean Hackers Attacking Drug Companies to Deploy Malware Via Weaponized Excel Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 North Korean state-sponsored hackers from the Kimsuky group have launched a targeted campaign against prescription pharmaceutical companies, using a cleverly disguised malware file named White Life Science ERP Specification. The attack uses a fake Excel document to …

Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage payloads inside JPEG image files and TXT documents, making it …

Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 27, 2026 Multiple vulnerabilities in the CODESYS Control runtime, one of the world’s most widely adopted software-based programmable logic controller (Soft PLC) platforms. According to Nozomi Networks Labs researchers, by chaining these security flaws, an authenticated attacker can replace …

Top 10 Best NDR (Network Detection and Response) Solutions in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Best NDR Solutions In the modern enterprise, the network is the ultimate source of ground truth. As organizations accelerate their digital transformation and adopt complex, cloud-native security architectures, the traditional perimeter has dissolved. Threat actors routinely bypass endpoint defenses using …

73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to …

Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued a full patch. Security researchers confirmed the flaw allowed threat …

New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented by Kaspersky application security specialist Haidar Kabibo at Black Hat …

CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 25, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly valued targets for cybercriminals because they provide direct pathways into …