PyPI package delivers ZiChatBot malware via Zulip API on Windows and Linux

Ravi LakshmananMay 7, 2026Malware/Threat Intelligence Cybersecurity researchers have discovered three packages in the Python Package Index (PyPI) repository designed to covertly deliver a previously unknown malware family called ZiChatBot to Windows and Linux systems. “While these wheel packages implement the functionality described on the PyPI web page, their true purpose is to covertly deliver malicious […]
Vulnerability in vm2 Node.js library allows sandbox escape and arbitrary code execution

Ravi LakshmananMay 7, 2026Vulnerabilities/Software Security More than a dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by malicious actors to breach the sandbox and execute arbitrary code on susceptible systems. vm2 is an open source library used to run untrusted JavaScript code in a secure sandbox by […]
Mirai-based xlabs_v1 botnet exploits ADB to hijack IoT devices and launch DDoS attacks

Cybersecurity researchers have published a new Mirai-derived botnet that targets internet-exposed devices that self-identify as xlabs_v1 and are running Android Debug Bridge (ADB), allowing them to join the network to perform distributed denial of service (DDoS) attacks. Hunt.io, which detailed the malware, said it discovered it after identifying a published directory on a server with […]
MuddyWater uses Microsoft Teams to steal credentials in false flag ransomware attack

An Iranian state-backed hacking group known as MuddyWater (also known as Mango Sandstorm, Seedworm, and Static Kitten) is believed to have been responsible for the ransomware attack, dubbed a “false flag operation.” This attack, observed by Rapid7 in early 2026, was found to utilize social engineering techniques via Microsoft Teams to initiate the infection sequence. […]
The Hacker News launches “Cybersecurity Stars Awards 2026” — now accepting applications

hacker newsMay 6, 2026Security Leadership/Industry Recognition For nearly 20 years, we at Hacker News have been primarily reporting horror stories about cyberspace: massive hacks, broken systems, and new threats. But behind every headline there’s a quieter, better story. This is the story of leaders who make tough decisions under pressure, teams who build smarter defenses, […]
The AI agent is already within the perimeter. Do you know what they do?

Analysts recently confirmed what identity security teams have been quietly worrying about. That means AI agents are being deployed faster than companies can manage. Gartner states in its first Market Guide for Guardian Agents that “enterprise adoption of AI agents is accelerating and outpacing the maturity of governance policy management.” Business leaders can request access […]
Google’s Android app receives public certification to thwart supply chain attacks

Ravi LakshmananMay 6, 2026Android / data security Google announced binary transparency enhancements for Android as a way to protect its ecosystem from supply chain attacks. Google’s product and security teams said, “This new public ledger ensures that the Google apps on devices are exactly what we intended them to be built and distributed.” This effort […]
CloudZ RAT exploits Windows Phone links to steal credentials and OTPs

Ravi LakshmananMay 6, 2026Endpoint security/threat intelligence Cybersecurity researchers have detailed an intrusion that involved the use of the CloudZ remote access tool (RAT) and an earlier undocumented plugin called Pheno to facilitate credential theft. “Based on the functionality of the CloudZ RAT and Pheno plugin, it was intended to steal victims’ credentials and potentially one-time […]
Palo Alto PAN-OS vulnerability exploited to allow remote code execution

Ravi LakshmananMay 6, 2026Vulnerability/Network Security Palo Alto Networks has issued an advisory warning that a critical buffer overflow vulnerability in PAN-OS software is being exploited in the wild. This vulnerability is tracked as CVE-2026-0300 and is described as a case of unauthenticated remote code execution. If the User Identity Authentication Portal is configured to allow […]
Critical flaw in Apache HTTP/2 (CVE-2026-23918) allows DoS and potential RCE

Ravi LakshmananMay 5, 2026Vulnerabilities / Server Security The Apache Software Foundation (ASF) has released security updates that address several security vulnerabilities in its HTTP server, including a serious vulnerability that could lead to remote code execution (RCE). The vulnerability is tracked as CVE-2026-23918 (CVSS score: 8.8) and is described as a case of “double free […]