Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing …

New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in …

GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in …

PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly …

ShinyHunters Claims Credit for Cyber-Attack on Online Learning Management System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A recent cyberattack targeting an online Learning Management System (LMS) has been attributed to the notorious cybercriminal group ShinyHunters. The incident caused widespread service disruptions affecting educational …

GitHub Source Code Breach – TeamPCP Claims Access to Internal Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 20, 2026 A notorious threat actor operating under the alias TeamPCP claims to have breached GitHub’s internal systems, allegedly exfiltrating proprietary organization data and source code. The attackers are offering the …

UAC-0184 Malware Chain Uses bitsadmin and HTA Files for Gated Payload Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A newly documented attack chain linked to the threat group UAC-0184 has been observed using Windows’ built-in bitsadmin tool and HTA files to sneak malicious payloads onto …

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 A ransomware group called The Gentlemen has been quietly building one of the most aggressive cybercriminal operations seen in recent years. Emerging publicly in the second half …

Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 19, 2026 North Korea-linked hackers are at it again, and this time they are casting a wide net. The Kimsuky threat group, a well-known cyber espionage unit with ties …