Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal …

Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet’s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability …

Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers …

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login …

Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, …

Email-Borne Worm Surge Drives New Threat Wave Across Industrial Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global wave of email-borne worms hit industrial control systems (ICS) in the fourth quarter of 2025, marking one of the most concerning threat shifts seen across operational technology (OT) environments in recent years. The surge was largely tied to …

Fake Zoom SDK Update Delivers Sapphire Sleet Malware in New macOS Intrusion Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean threat actor known as Sapphire Sleet has launched a new campaign against macOS users, using a fake Zoom SDK update to trick victims into running malicious files that steal passwords, cryptocurrency assets, and personal data. Unlike attacks …

Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the marimo Python notebook platform is now being actively used by attackers to deploy a blockchain-powered backdoor on developer systems. The flaw, tracked as CVE-2026-39987, allows remote code execution without authentication, making it a dangerous entry …

Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Brazilian cybersecurity researcher has exposed a sophisticated, large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold through a Chinese marketplace, devices engineered from the ground up to silently drain cryptocurrency across roughly 20 blockchains. The …

Anthropic Releases Claude Opus 4.7 with Automated Real-Time Cybersecurity Safeguards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has launched Claude Opus 4.7, its latest flagship model, combining improved coding and vision capabilities with automated real-time safeguards to detect and block high-risk cybersecurity requests. The release is notable because Anthropic is testing these protections on a broadly …