Cybercriminal groups exploit Vishing and SSO in rapid SaaS extortion attacks

Ravi LakshmananMay 1, 2026 Cybersecurity researchers are warning of two cybercrime groups that are carrying out “fast, high-impact attacks” mostly within the confines of SaaS environments, while minimizing the footprint of their activities. The clusters Cordial Spider (also known as BlackFile, CL-CRI-1116, O-UNC-045, and UNC6671) and Snarky Spider (also known as O-UNC-025 and UNC6661) are […]
China-linked hackers target Asian governments, NATO states, journalists, activists

Cybersecurity researchers have revealed details of a new Chinese-linked espionage operation targeting government and defense sectors across South, East and Southeast Asia, as well as European governments in NATO. Trend Micro has determined that this activity is the result of a threat activity cluster tracked under the temporary designation SHADOW-EARTH-053. This hostile group is assessed […]
5 sales challenges impacting MSP cybersecurity revenue

Managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030[1]cybersecurity is the fastest growing field[2]. Despite this opportunity, many MSPs are holding back on revenue because their go-to-market strategies fail to connect technical expertise with business needs. This execution gap is what causes most trades to stall. […]
Two cybersecurity experts sentenced to four years in prison for BlackCat ransomware attack

Ravi LakshmananMay 1, 2026Data Breach/Law Enforcement The US Department of Justice (DoJ) announced Thursday that two cybersecurity experts will each be sentenced to four years in prison for facilitating the 2023 BlackCat ransomware attack. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, are accused of deploying ransomware to multiple victims across the […]
Tainted Ruby Gems and Go Modules Abuse CI Pipelines to Steal Credentials

Ravi LakshmananMay 1, 2026Supply chain attacks/malware New software supply chain attack campaigns have been observed using sleeper packages as a vector to then push malicious payloads that enable credential theft, GitHub Actions modification, and SSH persistence. This activity is believed to be the work of the GitHub account ‘BufferZoneCorp’, which published a set of repositories […]
PyTorch Lightning and Intercom Client Suffer Supply Chain Attack to Steal Credentials

Ravi LakshmananApril 30, 2026Supply chain attacks/malware In yet another software supply chain attack, attackers compromised the popular Python package Lightning and pushed two malicious versions to perform credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both published on April 30, 2026. The campaign […]
SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

Ravie LakshmananApr 30, 2026Hacking News / Cybersecurity News The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to […]
New Python backdoor uses tunneling service to steal browser and cloud credentials

Ravi LakshmananApril 30, 2026Cloud security/threat intelligence Cybersecurity researchers have revealed details of a stealth Python-based backdoor framework called DEEP#DOOR that has the ability to establish persistent access and collect a wide range of sensitive information from compromised hosts. “The compromise chain begins with the execution of a batch script (‘install_obf.bat’) that disables Windows security controls, […]
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers, and security analysts by impersonating administrative utilities they rely on for daily operations. By integrating Search Engine Order (SEO) poisoning, a dual-stage GitHub distribution architecture, and decentralized blockchain-based […]
New Linux ‘copy failure’ vulnerability allows root access on major distributions

Ravi LakshmananApril 30, 2026Linux / Vulnerabilities Cybersecurity researchers have revealed details of a Linux local privilege escalation (LPE) flaw that could allow unprivileged local users to gain root. This high-severity vulnerability, tracked as CVE-2026-31431 (CVSS score: 7.8), has been codenamed Copy Fail by Xint.io and Theori. “An unprivileged local user can write a controlled 4 […]