Saturday, May 2, 2026
HomeCyber News

Cyber News

New BIND 9 Vulnerabilities Put Organizations at Risk of Cache Poisoning and DoS Attacks

Two critical vulnerabilities in BIND 9, one of the most widely deployed DNS server software solutions globally. Released on July 16, 2025, these security vulnerabilities pose significant risks to organizations running affected versions, potentially exposing them to cache poisoning attacks and denial-of-service incidents...

Malicious Actors Exploit WordPress Sites to Redirect Users to Harmful Destinations

Last month, cybersecurity experts uncovered a sophisticated malware campaign targeting WordPress websites that stealthily redirects visitors to malicious domains. The threat actors embedded their malicious payload deep within core files, enabling search engine poisoning and unauthorized content injection without raising immediate alarms. A detailed...

Microsoft Entra ID Vulnerability Enables Privilege Escalation to Global Administrator

A critical vulnerability in Microsoft's Entra ID (formerly Azure Active Directory) that allows attackers to escalate privileges and impersonate any user with Global Administrator privileges. The privilege escalation technique leverages a fundamental weakness in how Microsoft's first-party applications handle authentication credentials. Attackers who compromise...

Cybercriminals Leveraging DNS Gaps to Conceal and Distribute Malware

A sophisticated technique where threat actors are exploiting DNS infrastructure to hide malware and establish persistent command-and-control communications, turning the internet's foundational addressing system into an unwitting storage and delivery platform for malicious software. The discovery, made through analysis of passively collected DNS records in...

US National Guard Network Breached by Chinese ‘Salt Typhoon’ Hackers for Almost a Year

A sophisticated Chinese cyberspy group known as Salt Typhoon penetrated at least one state's National Guard network for nearly ten months, accessing sensitive military and law enforcement information in what represents a significant escalation of Beijing's cyber operations against American defense infrastructure. The breach,...

Crypto Wallets Targeted by Dark Partners – Hackers Exploit Fake AI Tools and VPN Services

A sophisticated cybercrime group known as Dark Partners has been orchestrating large-scale cryptocurrency theft campaigns since May 2025, utilizing an extensive network of fake websites that impersonate popular AI tools, VPN services, and crypto wallet applications. The financially motivated gang has established operations across...