Tuesday, May 5, 2026
HomeCyber News

Cyber News

ClamAV Versions 1.4.3 and 1.0.9 Launch with Patch for Remote Code Execution Vulnerability

Today marks a significant milestone for the open-source antivirus community as ClamAV releases versions 1.4.3 and 1.0.9. These patch releases address critical security vulnerabilities, including a dangerous buffer overflow that could enable remote code execution, along with several other important fixes and architectural improvements....

Python Malware Targets Windows Systems Through Cloudflare Tunnels Exploited by Hackers

A new wave of cyberattacks, dubbed SERPENTINE#CLOUD, is leveraging Python, Cloudflare tunneling services, and deceptive file tactics to compromise Windows computers worldwide stealthily. This evolving campaign, uncovered by Securonix researchers, exhibits a multi-layered infection chain that blends social engineering with advanced technical evasion, marking...

Cybercriminals Use VBScript to Deploy Masslogger Credential Stealer Malware

Security researchers at Seqrite Labs have uncovered a new wave of sophisticated cyberattacks where cybercriminals utilize encoded VBScript (.VBE) files as the initial infection vector for deploying the Masslogger credential stealer malware. This campaign exemplifies the evolving threat landscape, with attackers leveraging advanced, multi-stage, fileless...

Cybercriminals Exploit Cloudflare Tunnels to Deploy Covert Python Malware

In a recent surge of cyberattacks, threat actors are abusing Cloudflare’s legitimate tunneling service to deliver stealthy malware, according to a detailed report from Securonix threat researchers. The campaign, dubbed SERPENTINE#CLOUD, employs a multi-stage infection chain initiated by malicious shortcut files (.lnk) masquerading as harmless...

Golden SAML Exploit – Attackers Seize Control of Federation Server’s Private Key

In a striking reminder of the fragility underlying digital identity systems, cybersecurity experts have issued new warnings about the potential for “Golden SAML” attacks a sophisticated exploit enabling threat actors to seize control over authentication processes by stealing the private keys used by federation...

Stay Alert – Fake CAPTCHA Pop-ups Are Covertly Installing LightPerlGirl Malware

In an era where cyber threats evolve with alarming frequency, a new malware strain dubbed LightPerlGirl is making waves as it exploits users’ trust in web CAPTCHA systems. Security researchers at Todyl have uncovered a sophisticated attack chain that leverages fake CAPTCHA pop-ups to trick users...