WebNews
Please enter a web search for web results.
NewsWeb
New Akira Lookalike Ransomware Campaign Targeting Windows Users in South America
4+ hour, 59+ min ago (650+ words) A new and dangerous ransomware campaign has surfaced across South America, targeting Windows users with a carefully crafted strain that closely imitates the well-known Akira ransomware. While the two may appear nearly identical on the surface, this new threat is…...
Hackers Clone CERT-UA Site to Trick Victims Into Installing Go-Based RAT
4+ hour, 56+ min ago (536+ words) A threat group recently set up a convincing fake version of Ukraine's official cybersecurity authority website to trick targets into downloading a dangerous remote access tool. The campaign, now tracked under the identifier UAC-0255, relied on a mix of phishing…...
Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign
6+ hour, 18+ min ago (606+ words) A seemingly routine procurement email has become the entry point for a sophisticated six-stage malware attack targeting industrial suppliers and procurement teams. The campaign, tracked as NKFZ5966PURCHASE, disguises itself as a Boeing Request for Quotation (RFQ) from a person named "Joyce…...
OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues
6+ hour, 17+ min ago (332+ words) The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review before upgrading. The flaw was reported by a researcher identified as "rabbit." OpenSSH developers note that exposing these…...
New ZAP PTK Add-On Maps Browser Security Findings as Native Alert Into ZAP
9+ hour, 44+ min ago (451+ words) The Zed Attack Proxy (ZAP) team has rolled out version 0.3.0 of the OWASP PenTest Kit (PTK) add-on, introducing a transformative workflow upgrade for application security testing. This new release bridges the critical gap between traditional proxy-level scanning and modern client-side…...
Cisco Smart Software Manager Vulnerability Let Attackers Execute Arbitrary Commands
10+ hour, 58+ min ago (386+ words) Cisco has issued an urgent security warning regarding a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem) platform. Enterprise organizations widely use this tool to manage their Cisco software licenses locally. Tracked as CVE-2026-20160, the flaw carries a…...
Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication
13+ hour, 45+ min ago (352+ words) Cisco has recently disclosed a critical security flaw affecting its Integrated Management Controller (IMC), prompting the release of urgent software updates. The vulnerability, officially tracked as CVE-2026-20093, has been assigned a critical Base CVSS score of 9.8, indicating the highest level of…...
Public PoC Exploit Released for Nginx-UI Backup Restore Vulnerability
18+ hour, 42+ min ago (433+ words) A critical security flaw has been disclosed in the Nginx-UI backup restore mechanism, tracked as CVE-2026-33026. This vulnerability allows threat actors to tamper with encrypted backup archives and inject malicious configurations during the restoration process. With a public Proof-of-Concept (PoC)…...
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries
14+ hour, 5+ min ago (537+ words) Cybercriminals are getting better at hiding their tracks, and a recently uncovered Remcos RAT campaign is proof of that. This attack does not rely on a single malicious file dropped onto a system. Instead, it uses a carefully built, multi-stage…...
Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges
14+ hour, 25+ min ago (351+ words) A high-severity security flaw has been identified in the Symantec Data Loss Prevention (DLP) Agent for Windows. Tracked as CVE-2026-3991, this vulnerability allows a low-privileged local attacker to escalate their system privileges to the highest level. Security researcher Manuel Feifel…...