<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
    <title>Cybersecurity Tomorrow &amp; : The Hacker News</title>
    <link>https://cybersecuritytomorrow.com/rss/category/the-hacker-news</link>
    <description>Cybersecurity Tomorrow &amp; : The Hacker News</description>
    <dc:language>en</dc:language>
    <dc:creator></dc:creator>
    <dc:rights>Copyright 2025 Cybersecurity Tomorrow &amp; All Rights Reserved.</dc:rights>
    <item>
        <title>FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks</title>
        <link>https://cybersecuritytomorrow.com/fbi-warns-russian-hackers-target-signal-whatsapp-in-mass-phishing-attacks</link>
        <guid>https://cybersecuritytomorrow.com/fbi-warns-russian-hackers-target-signal-whatsapp-in-mass-phishing-attacks</guid>
        <description><![CDATA[ Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to seize control of accounts belonging to individuals with high intelligence value, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) said Friday.
&quot;The campaign ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiMsZnvgdoACYJn8WjDy_Lpvpy1iqvGpj-vb4hYfYTLujLp_5dm8WZKjl64LYwY4-MON0-1k8-F2K3KDu0QG7isYjhaMvre0E0vrqJCSP49r2j374JPbV6WvkTG8lwqwrxquX-3xrReaA3G-NQGvskSnlOtM1XRj1J3MdPuCK9lXC6vf8ZkrCizN6ohcLC/s1600/signal-whatsapp.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>FBI, Warns, Russian, Hackers, Target, Signal, WhatsApp, Mass, Phishing, Attacks</media:keywords>
    </item>
    <item>
        <title>Oracle Patches Critical CVE&amp;2026&amp;21992 Enabling Unauthenticated RCE in Identity Manager</title>
        <link>https://cybersecuritytomorrow.com/oracle-patches-critical-cve-2026-21992-enabling-unauthenticated-rce-in-identity-manager</link>
        <guid>https://cybersecuritytomorrow.com/oracle-patches-critical-cve-2026-21992-enabling-unauthenticated-rce-in-identity-manager</guid>
        <description><![CDATA[ Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.
The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0.
&quot;This vulnerability is remotely exploitable without authentication,&quot; Oracle said in an advisory. &quot;If successfully ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxIh9aqIMPc6elNLcqZwmxGq0BHfA3NS2kkxawAr-H7SzPJKmvc7tXrykcm664TGFkJUIb_BmGpJV0CkEjIxVoRfTCrc8br5bi_TL93Nv_g7J_c9ccucZL4e55lp_zyywwBeAzDIoA1bnI95ELRLCbOyVf0WX0CGgGHLun2uQFKhqeMKf16nBOeJTO7O77/s1600/oracle-flaw-hack.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Oracle, Patches, Critical, CVE-2026-21992, Enabling, Unauthenticated, RCE, Identity, Manager</media:keywords>
    </item>
    <item>
        <title>CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026</title>
        <link>https://cybersecuritytomorrow.com/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026</link>
        <guid>https://cybersecuritytomorrow.com/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026</guid>
        <description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come under exploitation are listed below -

CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJQDea3eiUAONNSYkmQsjicwXBMSALOAUJi7yPHqOStd9N-KBADSGXjH5zJS66VPyzi7-w5ULK7Ax9qH66_Av9E3xIL8BB7sDKz9d-ZbmlyqeyfKyCUYBb15eOH5_keQQ-RUchVoh7NvguG3Ps8sau8Ik17QNOMVtmTkQEck9gao_1zcLPE8JE_qPvc4Q9/s1600/cisa-kev.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>CISA, Flags, Apple, Craft, CMS, Laravel, Bugs, KEV, Orders, Patching, April, 2026</media:keywords>
    </item>
    <item>
        <title>Trivy Supply Chain Attack Triggers Self&amp;Spreading CanisterWorm Across 47 npm Packages</title>
        <link>https://cybersecuritytomorrow.com/trivy-supply-chain-attack-triggers-self-spreading-canisterworm-across-47-npm-packages</link>
        <guid>https://cybersecuritytomorrow.com/trivy-supply-chain-attack-triggers-self-spreading-canisterworm-across-47-npm-packages</guid>
        <description><![CDATA[ The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm.
The name is a reference to the fact that the malware uses an ICP canister, which refers to tamperproof smart contracts on ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJqn31IC9aCQ9LMLCLRXgpwsa1gvtzXlYk20-1yRmCMYVM_MwGHedfSgbKl24yaeTx4fqRc4-vscge-d3P6sN8sErQBVGD0kgxMGzV-mDCI1wGFh87BB8me019zcennhvA6xyMHLnH9IKZ-txSWs9OwL5cGbg0X8sx_KZ2tj5A5awErRRRMbdSrw_cXs6a/s1600/npm-malware.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Trivy, Supply, Chain, Attack, Triggers, Self-Spreading, CanisterWorm, Across, npm, Packages</media:keywords>
    </item>
    <item>
        <title>Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets</title>
        <link>https://cybersecuritytomorrow.com/trivy-security-scanner-github-actions-breached-75-tags-hijacked-to-steal-cicd-secrets</link>
        <guid>https://cybersecuritytomorrow.com/trivy-security-scanner-github-actions-breached-75-tags-hijacked-to-steal-cicd-secrets</guid>
        <description><![CDATA[ Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets.
The latest incident impacted GitHub Actions &quot;aquasecurity/trivy-action&quot; and &quot;aquasecurity/setup-trivy,&quot; which are used to scan Docker container images for vulnerabilities and set up GitHub Actions workflow ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNf7vYlImTCJ7BCjYYEhoFZXTawhHcJJad9cFjQn98oQjaPY9HY6Qgpp6pAyqkq7CNHyVXI9fR8hcyVNlW_knYia3f0BhAlK7fZb2gplznk9v9QCFGKtIbMLTSu-erTslOxZCHd8jkJKXIcCYhK8QkKLuWjG8yxjhPBaEWUDzwY0sUkX5JvhBtzFxyfp_q/s1600/scan.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Trivy, Security, Scanner, GitHub, Actions, Breached, Tags, Hijacked, Steal, CICD, Secrets</media:keywords>
    </item>
    <item>
        <title>Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems</title>
        <link>https://cybersecuritytomorrow.com/rogue-npm-packages-mimic-telegram-bot-api-to-plant-ssh-backdoors-on-linux-systems</link>
        <guid>https://cybersecuritytomorrow.com/rogue-npm-packages-mimic-telegram-bot-api-to-plant-ssh-backdoors-on-linux-systems</guid>
        <description><![CDATA[ Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities.
The packages in question are listed below -

node-telegram-utils (132 downloads)
node-telegram-bots-api (82 downloads)
node-telegram-util (73 downloads)


According to supply chain ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTYaPrg3QcUDzJQw_6M2cQ8mylAmeTI7yDB2gTcrkFTeuN-nmzQGrSavv6DL8aU7gs55EFPkfLJM_rYvi1lm8wCbOK3OKftPnP9DR_HJbvbzvnvevxMUQRwOX0xd6qSZ0Is0f-eWZJFTknWvr4IoD2Qu4sZxmlmtn8nTW9yOOHbiFgeNyzc8cv5Wb9Z1X2/s1600/linux.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Rogue, npm, Packages, Mimic, Telegram, Bot, API, Plant, SSH, Backdoors, Linux, Systems</media:keywords>
    </item>
    <item>
        <title>ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware</title>
        <link>https://cybersecuritytomorrow.com/asus-confirms-critical-flaw-in-aicloud-routers-users-urged-to-update-firmware</link>
        <guid>https://cybersecuritytomorrow.com/asus-confirms-critical-flaw-in-aicloud-routers-users-urged-to-update-firmware</guid>
        <description><![CDATA[ ASUS has disclosed a critical security flaw impacting routers with AiCloud enabled that could permit remote attackers to perform unauthorized execution of functions on susceptible devices.
The vulnerability, tracked as CVE-2025-2492, has a CVSS score of 9.2 out of a maximum of 10.0.

&quot;An improper authentication control vulnerability exists in certain ASUS router firmware series,&quot; ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC2Znl4UHn2tC-NlTNtOaYJ7AhGRK7pH53LZWvxGtpnAr2WN-GQskGoscwZOOmp3j0TVSIRyeikiPUzIDN0MjkhWORr4owD4Tf7XhxzqtBGOlIEw36eGHe8fohgwJ8wtJakc7Uobm0uFShLjbiUrULgk9pNIJrLwOBBSmRH0RByY5885RDyvEqSXL8ytRB/s1600/asus-ai.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>ASUS, Confirms, Critical, Flaw, AiCloud, Routers, Users, Urged, Update, Firmware</media:keywords>
    </item>
    <item>
        <title>Chinese Smishing Kit Powers Widespread Toll Fraud Campaign Targeting U.S. Users in 8 States</title>
        <link>https://cybersecuritytomorrow.com/chinese-smishing-kit-powers-widespread-toll-fraud-campaign-targeting-us-users-in-8-states</link>
        <guid>https://cybersecuritytomorrow.com/chinese-smishing-kit-powers-widespread-toll-fraud-campaign-targeting-us-users-in-8-states</guid>
        <description><![CDATA[ Cybersecurity researchers are warning of a &quot;widespread and ongoing&quot; SMS phishing campaign that&#039;s been targeting toll road users in the United States for financial theft since mid-October 2024.
&quot;The toll road smishing attacks are being carried out by multiple financially motivated threat actors using the smishing kit developed by &#039;Wang Duo Yu,&#039;&quot; Cisco Talos researchers Azim Khodjibaev, Chetan ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTSFUr1LOmW273ZOVQRjrfUwSucPBc0LMRMS4l7mdYTxXLNPx-CbGJhJ_6FqNQamMtfdvDHg8jTDwC_2QBHVYZfU-5p_H9wxR5SQY4b2uBnhikXM6P9TsyzzI4SW3UU__EWK2MnGKeP9y-cdU1lku9l_zOjrGceurDqkr4Xb2BkKHbqcOGUGEgyBVScTFJ/s1600/phishing.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Chinese, Smishing, Kit, Powers, Widespread, Toll, Fraud, Campaign, Targeting, U.S., Users, States</media:keywords>
    </item>
    <item>
        <title>Multi&amp;Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoader</title>
        <link>https://cybersecuritytomorrow.com/multi-stage-malware-attack-uses-jse-and-powershell-to-deploy-agent-tesla-and-xloader</link>
        <guid>https://cybersecuritytomorrow.com/multi-stage-malware-attack-uses-jse-and-powershell-to-deploy-agent-tesla-and-xloader</guid>
        <description><![CDATA[ A new multi-stage attack has been observed delivering malware families like Agent Tesla variants, Remcos RAT, and XLoader.
&quot;Attackers increasingly rely on such complex delivery mechanisms to evade detection, bypass traditional sandboxes, and ensure successful payload delivery and execution,&quot; Palo Alto Networks Unit 42 researcher Saqib Khanzada said in a technical write-up of the campaign.
The ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKoTKuU3COGDSwy46uJfXpH99uyAvSuu8NEgeTJH6Co4hNRWbDcKB6EpP-bRz3ZDeNpv8N9v5RRjZHRrB5d657WYF4jjiQ7uzAEzDoevTU5HCSBe85S9PwvuJ9x9NYjYiPYE9HYTpry-dMYseQ4YNcE3jWJ28a6nZ9Wn5Q0xkFct_rKw3blJi2zzS7nBDd/s1600/malware-infection.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Multi-Stage, Malware, Attack, Uses, .JSE, and, PowerShell, Deploy, Agent, Tesla, and, XLoader</media:keywords>
    </item>
    <item>
        <title>[Webinar] AI Is Already Inside Your SaaS Stack — Learn How to Prevent the Next Silent Breach</title>
        <link>https://cybersecuritytomorrow.com/webinar-ai-is-already-inside-your-saas-stack-learn-how-to-prevent-the-next-silent-breach</link>
        <guid>https://cybersecuritytomorrow.com/webinar-ai-is-already-inside-your-saas-stack-learn-how-to-prevent-the-next-silent-breach</guid>
        <description><![CDATA[ Your employees didn’t mean to expose sensitive data. They just wanted to move faster. So they used ChatGPT to summarize a deal. Uploaded a spreadsheet to an AI-enhanced tool. Integrated a chatbot into Salesforce. No big deal—until it is.
If this sounds familiar, you&#039;re not alone. Most security teams are already behind in detecting how AI tools are quietly reshaping their SaaS environments. And ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOWn65wd33dg2uO99NrtKbpYLfcepwOLidQDMls0HXKlA91k6HURluRA4WXgJRAZldEe1VReMQZyyYt1PgnoAn5JPpILsWlXIzmrBSs_TBoyPwO7hZrWouBg2-O3mdeoeSGY-l9_bsZB7vbpKjTSvG93zNytjxgTaMPqo9iq9Z5pGa05CJOs9uXpwHFT4/s1600/ai-cyber.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Webinar, Already, Inside, Your, SaaS, Stack, —, Learn, How, Prevent, the, Next, Silent, Breach</media:keywords>
    </item>
    </channel>
</rss>