Tuesday, May 5, 2026
HomeCyber News

Cyber News

Katz Stealer Upgrades – Advanced Credential Theft with System Fingerprinting and Persistence Tactics

Cybersecurity researchers have issued fresh warnings following the discovery of significant upgrades to the Katz Stealer, a rapidly evolving information-stealing malware that has gained prominence among cybercriminal groups throughout 2025. According to in-depth analyses, Katz Stealer now leverages a sophisticated combination of stealthy persistence mechanisms,...

OPPO Clone Phones Weak WiFi Hotspot Poses Risk to Sensitive Data

A critical security vulnerability has been discovered in OPPO Clone Phone devices that could expose users' sensitive information through poorly secured WiFi hotspots used for file transfers. The vulnerability , designated as CVE-2025-27387 and published to the GitHub Advisory Database, represents a high-severity...

PyPI Repositories Targeted – Hackers Deploy Malicious Packages to Steal AWS, CI/CD, and macOS Data

In a stark reminder of the vulnerabilities inherent in open-source ecosystems, new revelations confirm that attackers are targeting Python Package Index (PyPI) repositories with sophisticated, multi-stage malware. Security firm JFrog recently identified and reported a malicious package, “chimera-sandbox-extensions,” uploaded by the user “chimerai.” Unlike...

Xiaomi App Vulnerability Allows Hackers to Gain Unauthorized Access to Devices

Xiaomi has disclosed a critical security vulnerability in its interoperability application that could allow attackers to gain unauthorized access to users' devices. The vulnerability, identified as CVE-2024-45347 with a severe CVSS score of 9.6, affects millions of Xiaomi device users worldwide and highlights ongoing...

Uncovering Hidden Malware in JPEGs Using Steganography and Base64

Security researchers continually refine their tactics to detect the latest malware delivery methods. One increasingly common technique is the use of steganography to hide malicious payloads within seemingly innocuous files, such as images. This article explores a real-world case where malware was concealed within...

WinRAR Directory Vulnerability Allows Arbitrary Code Execution via Malicious File

A critical security vulnerability has been discovered in RARLAB's popular WinRAR archiving software that allows remote attackers to execute arbitrary code on affected systems through directory traversal exploitation. The vulnerability, designated as CVE-2025-6218 with a CVSS score of 7.8, affects WinRAR installations and requires...