Monday, May 4, 2026
HomeCyber News

Cyber News

APT-C-36 – Cyber Assaults Targeting Government, Financial, and Critical Infrastructure Sectors

Since 2018, the advanced persistent threat group known as APT-C-36, or Blind Eagle, has been waging a relentless cyber assault campaign targeting organizations across Latin America, with a particular focus on Colombia. The group’s operations have consistently threatened government institutions, financial organizations, and critical...

Writable File in Lenovo Windows Directory Allows Stealthy AppLocker Bypass

A significant vulnerability affecting Lenovo machines that allows users to bypass AppLocker security controls through a writeable file located in the Windows system directory. The issue, discovered by Oddvar Moe from TrustedSec, involves improper file permissions on the MFGSTAT.zip file that comes preinstalled with...

Critical HIKVISION applyCT Vulnerability Exposes Devices to Remote Code Execution Risks

A critical vulnerability in HIKVISION's applyCT security management platform that could allow attackers to execute arbitrary code on affected systems without authentication. The vulnerability, designated CVE-2025-34067, has been assigned the maximum CVSS score of 10.0, indicating its severe impact on enterprise security infrastructure. The vulnerability...

Phishing Attack Exploits Microsoft 365 Direct Send, Impersonates Internal Users

A recent wave of sophisticated phishing attacks has successfully bypassed traditional email security measures by exploiting a lesser-known feature within Microsoft 365: the Direct Send functionality. Security researchers from Varonis’ Managed Data Detection and Response (MDDR) Forensics team have uncovered a large-scale campaign targeting...

Critical PHP Vulnerabilities Enable SQL Injection and DoS Attacks – Update Immediately

Critical security vulnerabilities have been discovered in PHP's PostgreSQL and SOAP extensions that could enable SQL injection attacks and denial of service conditions. The vulnerabilities affect multiple PHP versions and require immediate patching to prevent potential exploitation by malicious actors. A significant security vulnerability has...

Israeli Cybersecurity Experts and Professors Targeted by Iranian APT35 Hackers

Amid heightened tensions between Iran and Israel, cybersecurity researchers have uncovered a sophisticated and ongoing cyber-espionage campaign targeting Israeli journalists, high-profile cybersecurity experts, and computer science professors from leading Israeli universities. The operation, attributed to the Iranian threat group known as Educated Manticore (also...