PyrsistenceSniper – Tool that Detects 117 Persistence Malware Techniques on Windows, Linux, and macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 24, 2026 PyrsistenceSniper is an advanced tool for detecting offline persistence, enabling cybersecurity analysts to identify 117 separate persistence mechanisms across Windows, Linux, and macOS platforms. Originally inspired by Autoruns and PersistenceSniper, this Python-based solution developed by Hexastrike enables …

Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 23, 2026 A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip, the vulnerability affects both NGINX Plus and NGINX …

Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 23, 2026 A multi-stage intrusion attack where a threat actor exploited an internet-facing F5 BIG-IP edge appliance as the entry point for a widespread, identity-focused attack that ultimately accessed Active Directory. According to Microsoft’s Defender Security Research, the attack …

Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 23, 2026 A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub …

Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 23, 2026 Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actors can exploit it. In its first month, the project leveraged the unreleased …

Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberattacks. A newly released threat intelligence report reveals that more than 1,350 active command-and-control …

World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented set of 79 fraudulent domains has ballooned into a network of at least …

Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that uses six separate persistence layers to stay embedded on compromised servers. The campaign …

Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Ubiquiti Networks has released urgent security updates to address a series of highly critical vulnerabilities affecting its UniFi OS platform. These severe flaws could allow unauthenticated, remote attackers to execute arbitrary code, escalate privileges, and severely compromise …

LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on Linux hosting servers. The bug is tracked as CVE‑2026‑48172 and …