Aggregator
CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs
CVE-2026-43063 | Linux Kernel up to 6.12.79/6.18.20/6.19.10 xfs xfs_attri_recover_work privilege escalation (WID-SEC-2026-1385)
CVE-2026-43061 | Linux Kernel up to 6.19.9 dmaengine_terminate_async deserialization (WID-SEC-2026-1385)
CVE-2026-43062 | Linux Kernel up to 6.19.9 Bluetooth l2cap_ecred_reconf_rsp type confusion (WID-SEC-2026-1385)
CVE-2026-43059 | Linux Kernel up to 6.12.77/6.18.19/6.19.9 Bluetooth mgmt_pending_valid use after free (WID-SEC-2026-1385)
CVE-2026-43060 | Linux Kernel up to 6.19.9 netfilter privilege escalation (WID-SEC-2026-1385)
Critical vm2 sandbox bug lets attackers execute code on hosts
Восстание против π: физики и программисты объявили войну самому известному числу в науке
CloudZ RAT Abuses Microsoft Phone Link to Steal SMS OTPs and Mobile Notifications
A newly discovered threat is turning a built-in Microsoft feature into a powerful spying tool. Security researchers have found a remote access tool called CloudZ that works alongside a custom plugin named Pheno to silently intercept SMS messages and one-time passwords (OTPs) from mobile phones, all without ever touching the phone itself. The attack exploits […]
The post CloudZ RAT Abuses Microsoft Phone Link to Steal SMS OTPs and Mobile Notifications appeared first on Cyber Security News.
Weekly Threat Bulletin – May 6th, 2026
New Cisco DoS flaw requires manual reboot to revive devices
Palo Alto Networks security advisory (AV26-425) – Update 1
QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise
A new and previously undocumented Linux threat has emerged, targeting software developers in a way that could put entire supply chains at risk. Named Quasar Linux, or QLNX, this malware operates as a full-featured remote access trojan built specifically for Linux systems. It combines stealth techniques with targeted credential theft, making it one of the […]
The post QLNX Targets Developers With Credential Theft Designed for Supply Chain Compromise appeared first on Cyber Security News.
Тихая месть Безоса: пока SpaceX взрывает прототипы, Blue Origin готовит рабочий лунный корабль
ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users
Samsung mobile security advisory (AV26-429)
New CISA initiative aims for critical infrastructure to operate offline during cyberattacks
WatchGuard security advisory (AV26-428)
Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison
A Latvian national operating out of Moscow was sentenced to 102 months in federal prison for his central role in a sprawling Russian ransomware syndicate. Deniss Zolotarjovs, 35, served as a primary extortionist and negotiator for a highly organized cybercriminal network that attacked over 54 companies worldwide. The United States Justice Department announced the sentencing, […]
The post Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison appeared first on Cyber Security News.