Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Four malicious npm packages capable of stealing SSH keys, cloud credentials, cryptocurrency wallets, and environment variables, while one variant quietly transforms infected machines into a DDoS botnet. …

CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying …

1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used WordPress plugin powering over one million websites has been hit by two serious vulnerabilities that could allow attackers to steal sensitive data and access server files. Security researchers …

Microsoft Confirms Windows 11 Update Fails With Error 0x800f0922

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a critical installation failure affecting its May 2026 Patch Tuesday cumulative update for Windows 11, KB5089549, leaving users stranded with error code 0x800f0922 and, in some …

New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A critical Windows privilege escalation zero-day vulnerability dubbed “MiniPlasma” has emerged with a public proof-of-concept exploit that allows attackers to achieve SYSTEM-level privileges on fully patched Windows …

Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A critical vulnerability in a widely used WordPress plugin has exposed over 200,000 websites to full account takeover, raising urgent concerns across the security community. Discovered on …

Fast16 Malware Manipulated Nuclear Weapons Simulation Data to Sabotage Test Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Fast16 malware has been reclassified as a precision tool engineered not to disrupt nuclear warheads directly, but to quietly falsify the outcome of nuclear weapons test simulations …

Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 17, 2026 A threat actor infiltrated Grafana Labs’ GitHub environment, stealing a privileged token to download the company’s private codebase, and then attempted to extort the open-source observability giant …

First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 17, 2026 Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company’s notable hardware-level memory protection. …