Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks | Cybersecurity
Ravie LakshmananMay 04, 2026Vulnerability / Network Security A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service…
Read moreA week in security (April 27 – May 3) | Malware
Last week on Malwarebytes Labs: 3 easy-to-miss cybersecurity risks for small businesses Actively exploited cPanel bug exposes millions of websites to takeover More PayPal emails hijacked to deliver tech support…
Read moreGlobal Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M | Cybersecurity
A coordinated international operation involving U.S. and Chinese authorities has arrested at least 276 suspects and shut down nine scam centers used for cryptocurrency investment fraud schemes targeting Americans, resulting…
Read more3 easy-to-miss cybersecurity risks for small businesses | Malware
There’s a lot to security that isn’t necessarily “cyber.” It’s not all hackers or complex network attacks. Alongside traditional cyberattacks that deploy malware or exploit known software vulnerabilities, there are…
Read moreCISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV | Cybersecurity
Ravie LakshmananMay 03, 2026Vulnerability / Container Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known…
Read moreTrellix Confirms Source Code Breach With Unauthorized Repository Access | Cybersecurity
Ravie LakshmananMay 02, 2026Data Breach / Enterprise Security Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a “portion” of its source code. It…
Read more30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign | Cybersecurity
Ravie LakshmananMay 01, 2026Malware / Threat Intelligence A newly discovered Vietnamese-linked operation has been observed using a Google AppSheet as a “phishing relay” to distribute phishing emails with an aim…
Read moreCybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks | Cybersecurity
Ravie LakshmananMay 01, 2026Malware / Social Engineering Cybersecurity researchers are warning of two cybercrime groups that are carrying out “rapid, high-impact attacks” operating almost within the confines of SaaS environments,…
Read moreActively exploited cPanel bug exposes millions of websites to takeover | Malware
Security researchers are warning about a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). This is a critical, actively exploited authentication-bypass bug…
Read moreTop Five Sales Challenges Costing MSPs Cybersecurity Revenue | Cybersecurity
The managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030[1], with cybersecurity being the fastest-growing sector[2]. Despite this opportunity, many MSPs…
Read moreMore PayPal emails hijacked to deliver tech support scams | Malware
Scammers have found another way to get deceptive messages delivered through PayPal’s legitimate services. In December 2025, we reported that PayPal closed a loophole that let scammers send real emails…
Read morePyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials | Cybersecurity
Ravie LakshmananApr 30, 2026Supply Chain Attack / Malware In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious…
Read moreHackers stole hundreds of thousands of Roblox accounts: Here’s what to do | Malware
More than 610,000 Roblox accounts were reportedly stolen. Was yours or your child’s among them? Ukrainian police arrested three individuals in Lviv who allegedly orchestrated one of the largest Roblox…
Read moreThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories | Cybersecurity
Ravie LakshmananApr 30, 2026Hacking News / Cybersecurity News The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam…
Read moreEtherRAT Distribution Spoofing Administrative Tools via GitHub Facades | Cybersecurity
Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers,…
Read moreScam-checking just got a lot easier: Malwarebytes is now in Claude | Malware
For years, Malwarebytes has protected people by going where they are, and where people are today is increasingly within AI tools. As these chatbots tackle more everyday questions—like what to wear for an interview, how…
Read moreResearchers built a chatbot that only knows the world before 1931 | Malware
The internet’s chatbots have read every forum rant, leaked Slack log, and confident blog post your uncle ever wrote about chemtrails. The results are predictable: they reflect the state of…
Read moreSAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack | Cybersecurity
Ravie LakshmananApr 29, 2026Supply Chain Attack / Malware Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to…
Read moreNew Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs | Cybersecurity
Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic’s Claude Opus large language model (LLM). The package…
Read moreMicrosoft won’t patch PhantomRPC: Feature or bug? | Malware
A researcher has discovered a weakness called PhantomRPC that Microsoft does not consider a vulnerability it plans to patch. PhantomRPC involves Windows Remote Procedure Call (RPC), the core of communication…
Read moreCISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV | Cybersecurity
Ravie LakshmananApr 29, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known…
Read moreLiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure | Cybersecurity
Ravie LakshmananApr 29, 2026Vulnerability / Cloud Security In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python…
Read moreResearchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push | Cybersecurity
Ravie LakshmananApr 28, 2026Vulnerability / Software Security Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to…
Read moreFake CAPTCHA scam turns a quick click into a costly phone bill | Malware
Researchers have documented a long‑running campaign that uses fake CAPTCHA pages to trick mobile users into sending dozens of international SMS messages in the background. If you’ve spent any time…
Read moreVECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi | Cybersecurity
Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption implementation across…
Read moreChinese engineer stole US military and NASA software for years | Malware
International espionage isn’t always about sophisticated malware and zero-day bugs. Sometimes it’s as simple as pretending to be someone else asking for a favor. For four years, a Chinese aerospace…
Read moreChinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks | Cybersecurity
Ravie LakshmananApr 28, 2026Cyber Espionage / Vulnerability A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy. Xu…
Read moreCheckmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack | Cybersecurity
Ravie LakshmananApr 27, 2026 Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company…
Read moreMythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side | Cybersecurity
Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious…
Read moreA week in security (April 20 – April 26) | Malware
Last week on Malwarebytes Labs: Medical data of 500,000 UK volunteers listed for sale on Alibaba How cyberattacks on companies affect everyone Apple fixes iOS bug that kept deleted notifications,…
Read more