ShinyHunters escalates Canvas attacks with school login defacements | Malware
Days after confirming a major data breach, Instructure is now facing a second blow. Earlier this week, Instructure confirmed a major data breach affecting its cloud‑hosted Canvas environment, with the…
Read moreTCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms | Cybersecurity
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security…
Read moreMicrosoft says Edge’s plaintext password behavior is “by design” | Malware
Some time ago, we discussed whether you should allow your browser to remember your passwords. In that article we mentioned the importance of encryption. “With a browser password manager, someone…
Read moreFake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads | Cybersecurity
Ravie LakshmananMay 08, 2026Android / Mobile Security Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories…
Read moreOne Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk | Cybersecurity
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report…
Read moreLinux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions | Cybersecurity
Ravie LakshmananMay 08, 2026Linux / Vulnerability Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as…
Read moreIvanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access | Cybersecurity
Ravie LakshmananMay 07, 2026Vulnerability / Network Security Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The…
Read moreMassive AI investment scam network spans 15,500 domains | Malware
Researchers tracked a large AI‑themed investment scam campaign involving more than 15,000 domains. It uses cloaking and deepfakes to hide from security tools while targeting ordinary users. Criminals abused the…
Read moreOne Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches | Cybersecurity
The Hacker NewsMay 07, 2026Artificial Intelligence / Threat Detection The hardest part of cybersecurity isn’t the technology, it’s the people. Every major breach you’ve read about lately usually starts the…
Read moreIf a fake moustache can fool age checks, is the Online Safety Act working? | Malware
A report based on a survey by the UK’s Internet Matters shows that much of the responsibility for managing the online safety of children still falls on families. The Online…
Read morePyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux | Cybersecurity
Ravie LakshmananMay 07, 2026Malware / Threat Intelligence Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware…
Read moreMillions of students’ personal data stolen in major education breach | Malware
Instructure, the company behind the Canvas learning management system (LMS), confirmed a cyber incident and subsequent data breach affecting its cloud‑hosted environment. The ShinyHunters ransomware group claims it is behind…
Read morevm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution | Cybersecurity
Ravie LakshmananMay 07, 2026Vulnerability / Software Security A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out…
Read moreMirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks | Cybersecurity
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying…
Read moreGoogle Chrome’s silent 4GB AI download problem | Malware
Google Chrome has been quietly downloading a 4GB AI model onto users’ devices without asking first. Security researcher Alexander Hanff, aka ThatPrivacyGuy, reports that Chrome has been silently installing Gemini…
Read moreAttackers adopt JavaScript runtime Bun to spread NWHStealer | Malware
In our previous research, we analyzed a Windows infostealer we track as NWHStealer. The attackers behind this stealer are continuously finding new methods to distribute the stealer. During our hunting activities, we noticed how attackers are using…
Read moreMuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack | Cybersecurity
The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a “false…
Read morePalo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution | Cybersecurity
Ravie LakshmananMay 06, 2026Vulnerability / Network Security Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the…
Read moreUpdate WhatsApp now: Two new flaws could expose you to malicious files | Malware
Meta has published a new security advisory for messaging app WhatsApp, announcing patches for two vulnerabilities. WhatsApp has fixed two security flaws that could be abused to interfere with how…
Read moreCritical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE | Cybersecurity
Ravie LakshmananMay 05, 2026Vulnerability / Server Security The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that…
Read moreWe Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is | Cybersecurity
While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses…
Read moreMicrosoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries | Cybersecurity
Microsoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains…
Read moreThe 2026 World Cup scam economy is already running before the first whistle | Malware
The FIFA World Cup 2026 is scheduled to begin June 11 across the US, Canada, and Mexico. The web is filling with sites impersonating ticket vendors, telecoms, sticker publishers, toy…
Read moreCyberattacks are raising your prices (Lock and Code S07E09) | Malware
This week on the Lock and Code podcast… Your prices could be going up because of a little something that one group has started calling the “cyber tax.” Not a…
Read morePhishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools | Cybersecurity
Ravie LakshmananMay 04, 2026Network Security / Endpoint Security An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM)…
Read more⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More | Cybersecurity
Ravie LakshmananMay 04, 2026Cybersecurity / Hacking This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels…
Read moreThousands of Facebook accounts stolen by phishing emails sent through Google | Malware
Researchers have uncovered a long-running phishing operation that abuses trusted Google services to hijack tens of thousands of Facebook accounts. The compromised Facebook accounts are mainly business and advertiser profiles,…
Read moreCritical cPanel Vulnerability Weaponized to Target Government and MSP Networks | Cybersecurity
Ravie LakshmananMay 04, 2026Vulnerability / Network Security A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service…
Read moreA week in security (April 27 – May 3) | Malware
Last week on Malwarebytes Labs: 3 easy-to-miss cybersecurity risks for small businesses Actively exploited cPanel bug exposes millions of websites to takeover More PayPal emails hijacked to deliver tech support…
Read moreGlobal Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M | Cybersecurity
A coordinated international operation involving U.S. and Chinese authorities has arrested at least 276 suspects and shut down nine scam centers used for cryptocurrency investment fraud schemes targeting Americans, resulting…
Read more