ZCyberNews
中文

Articles

432 articles

BRUSHWORM Backdoor and BRUSHLOGGER Keylogger Hit South Asian BankHIGH
Malware

BRUSHWORM Backdoor and BRUSHLOGGER Keylogger Hit South Asian Bank

Elastic Security Labs details BRUSHWORM, a modular backdoor spreading via USB, and BRUSHLOGGER, a DLL-side-loaded keylogger, targeting a South Asian financial institution.

2 min read
CrystalX RAT Combines Spyware, Stealer, and Prankware in MaaS OfferingHIGH
Malware

CrystalX RAT Combines Spyware, Stealer, and Prankware in MaaS Offering

Kaspersky details CrystalX RAT, a MaaS malware with spyware, credential theft, and prankware features targeting Windows users globally since mid-2025.

3 min readCrystalX
ESET: Cloud VMs Expose Critical Security Gaps in EnterpriseHIGH
Industry News

ESET: Cloud VMs Expose Critical Security Gaps in Enterprise

ESET warns that misconfigured cloud VMs—overprivileged IAM roles, exposed management ports, and unpatched OS images—create systemic security gaps across enterprise environments.

2 min read
ESET: March 2026 Cyber Threats Show Resilience GapsMEDIUM
Industry News

ESET: March 2026 Cyber Threats Show Resilience Gaps

ESET's Tony Anscombe warns that March 2026 attacks — including ransomware, supply chain compromises, and AI-driven phishing — reveal systemic gaps in organizational…

2 min read
Feds Disrupt IoT Botnets Behind Record DDoS AttacksHIGH
Industry News

Feds Disrupt IoT Botnets Behind Record DDoS Attacks

US DOJ, Canada, and Germany dismantled four IoT botnets — Aisuru, Kimwolf, JackSkid, Mossad — compromising 3M+ devices, enabling record-breaking DDoS attacks.

2 min read
Itron Breach: Utility Firm Discloses Internal IT Network IntrusionHIGH
Industry News

Itron Breach: Utility Firm Discloses Internal IT Network Intrusion

Itron disclosed a cybersecurity incident in an SEC 8-K filing: an unauthorized third party accessed internal IT systems.

2 min read
Kaspersky Details Coruna Exploit Kit Behind Operation TriangulationCRITICAL
Malware

Kaspersky Details Coruna Exploit Kit Behind Operation Triangulation

Kaspersky GReAT reveals Coruna framework used in Operation Triangulation: updated kernel exploits for CVE-2023-32434 and CVE-2023-38606 targeting iPhones with zero-click iMessage…

CVE-2023-32434CVE-2023-38606
3 min readOperation Triangulation
TrueConf Zero-Day CVE-2026-3502 Hit Southeast Asian GovtsHIGH
Vulnerabilities

TrueConf Zero-Day CVE-2026-3502 Hit Southeast Asian Govts

Check Point Research uncovered CVE-2026-3502, a 7.8-CVSS privilege escalation in TrueConf client, exploited in targeted attacks against Southeast Asian government entities since…

CVE-2026-3502
2 min read
VoidLink Rootkit Framework Combines LKM and eBPF for Linux PersistenceHIGH
Malware

VoidLink Rootkit Framework Combines LKM and eBPF for Linux Persistence

Elastic Security Labs dissects VoidLink, a Linux rootkit framework that blends Loadable Kernel Modules with eBPF hooks to evade detection and maintain stealthy persistence on…

3 min readVoidLink
ADT Breach Exposes Customer Data in Cyber IntrusionHIGH
Industry News

ADT Breach Exposes Customer Data in Cyber Intrusion

ADT confirmed cybercriminals breached its systems on April 20, 2026, stealing a limited set of customer and prospect data. No financial info or credentials compromised.

2 min read
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 DeadlineCRITICAL
Vulnerabilities

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Deadline

CISA added 4 actively exploited vulnerabilities to its KEV catalog — SimpleHelp, Samsung MagicINFO 9, and D-Link DIR-823X — with a May 2026 federal remediation deadline.

CVE-2024-57726
3 min read
Cyberattackers Weaponize Voltage Fluctuations Against Power GridsHIGH
Industry News

Cyberattackers Weaponize Voltage Fluctuations Against Power Grids

Dark Reading reports attackers are manipulating voltage to destabilize power grids — a growing cyber-physical threat vector targeting electricity infrastructure with no patch…

2 min readSandworm
← PrevPage 22 of 36Next →