Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software …

Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8. Administrators who can reproduce …

Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000 victims worldwide and generated at …

New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the …

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the “Noble Numbat” long-term support release, delivering a fresh installation image packed with the latest security patches, …

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. …

IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500 clients, has confirmed a data breach after a criminal marketplace …

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SloppyRAT is a remote access tool that appears designed to help ransomware operators move deeper into compromised networks. The malware arrives through ClickFix, a social-engineering method that tricks people into …

GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that could enable arbitrary file reads and credential theft. A separate …

JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take administrative control of exposed servers. The flaws, tracked as CVE-2026-42016, CVE-2026-42018, …