Microsoft Warns Jasper Sleet Uses Fake IT Worker Identities to Infiltrate Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked threat group is quietly getting hired by real companies. Jasper Sleet, a threat actor tied to North Korea, has been building fake professional identities and using them to land legitimate remote IT jobs, giving them direct access …

Claude Mythos AI Model Uncovers 271 Zero-Day Vulnerabilities in Firefox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s latest frontier AI model, Claude Mythos Preview, has identified a staggering 271 zero-day vulnerabilities in Mozilla Firefox marking a seismic shift in AI-powered cybersecurity defense. The findings, addressed in Firefox 150, represent the most significant single batch of security …

New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified backdoor called DinDoor is using the legitimate Deno JavaScript runtime and MSI installer files to quietly slip past security defenses and compromise targeted systems. The malware, tracked as a variant of the Tsundere Botnet, relies on trusted, …

Compromised Namastex npm Packages Deliver TeamPCP-Style CanisterWorm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious supply chain threat has surfaced in the npm ecosystem. Malicious versions of packages belonging to Namastex.ai have been found carrying CanisterWorm malware, a self-propagating backdoor that mirrors the attack style of the threat actor known as TeamPCP. The …

Massive SIM Farm-as-a-Service Network Exposes 87 Control Panels Across 17 Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global investigation has uncovered an industrial-scale mobile proxy ecosystem powered by a shared control platform called ProxySmart, with 87 exposed control panels spanning 17 countries and at least 94 physical phone-farm locations enabling large-scale fraud, bot activity, and identity …

Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to …

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability …

Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor …

Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the Microsoft.AspNetCore.DataProtection NuGet package. The out-of-band release was prompted after customers …

Unauthorized Group Gains Access to Anthropic’s Exclusive Cyber Tool Mythos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of unauthorized users has reportedly breached access controls surrounding Claude Mythos Preview, Anthropic’s powerful and closely guarded AI-driven cybersecurity tool, raising serious concerns about third-party vendor security and the risks of placing advanced offensive AI capabilities in the …