Wednesday, May 6, 2026
HomeCyber News

Cyber News

UNC1151 Targets Polish Entities via Roundcube Vulnerability in Spearphishing Campaign

A highly targeted spear phishing campaign has struck Polish organizations this week, leveraging a known Roundcube webmail vulnerability (CVE-2024-42009) to compromise user accounts and steal credentials. The operation, attributed with high confidence to the UNC1151 threat actor cluster linked by Mandiant and Google to...

Wireshark Vulnerability Allows DoS Attacks Through Malicious Packet Injection

Wireshark, the world’s most recognized and widely used network protocol analyzer, has recently come under scrutiny following the discovery of a critical vulnerability that could allow malicious actors to crash the software remotely. This vulnerability, officially designated CVE-2025-5601 and informally known as the Dissection...

Hackers Use Stealth Syscalls to Bypass EDR and Event Tracing

Researchers recently uncovered that the attackers are deploying advanced techniques to evade even the most secured security environments. The latest trend? Using stealthy, obfuscated system calls (syscalls) to bypass Endpoint Detection and Response (EDR) solutions and neutralize logging mechanisms like Event Tracing for Windows (ETW). How...

China Alleges Taiwan, Backed by the U.S., Is Behind Advanced Persistent Threat Operations

Chinese cybersecurity agencies, backed by leading research labs and security firms, have publicly accused Taiwan’s Information, Communications and Electronic Force Command (ICEFCOM), allegedly supported by the United States, of orchestrating a multi-year campaign of Advanced Persistent Threat (APT) attacks targeting critical infrastructure and sensitive...

Hackers Leverage Stealth Syscalls Technique to Bypass Event Tracing and EDR Systems

In a striking escalation of attack sophistication, advanced threat actors are now leveraging “stealth syscalls” to systematically evade Windows security monitoring tools including Event Tracing for Windows (ETW), Sysmon, and modern Endpoint Detection and Response (EDR) solutions. This new wave of malware employs multiple technical...

Fake WordPress Caching Plugin Steals Admin Credentials, Experts Warn Site Owners

Cybersecurity analysts have issued a stark warning to WordPress site owners after uncovering a sophisticated fake caching plugin, dubbed wp-runtime-cache, that silently exfiltrates admin credentials. The malicious plugin, discovered during a routine malware scan, exploits WordPress’s plugin architecture and cleverly masks its presence, making detection...