Category: Cyber Security

  • Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2

    Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2 A new and highly sophisticated malware loader has been found hiding inside what appears to be a harmless Minecraft mod. Researchers have uncovered a campaign that blends blockchain technology and social engineering to steal player credentials and deliver additional malicious payloads. The damage is…

  • CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

    CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to apply patches immediately amid active exploitation in the wild. The flaw, tracked as CVE-2026-20230, enables…

  • Microsoft Extends Windows 10 Security Updates for Users Up to October 2027

    Microsoft Extends Windows 10 Security Updates for Users Up to October 2027 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond the program’s originally planned expiration date of October 12, 2026. Windows 10 officially reached its end…

  • OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud

    OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and running financial…

  • Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware

    Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware A newly discovered malware family is making its way onto systems worldwide by hiding inside fake software installers that look completely legitimate. Researchers have identified a campaign where attackers disguise their malicious tools as trusted programs like Cisco AnyConnect and Google Update, tricking…

  • Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks

    Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks Google has released a critical security update for its Chrome browser, pushing the Stable channel to version 149.0.7827.196/197 for Windows and Mac, and 149.0.7827.196 for Linux. The update addresses 18 security vulnerabilities, including four rated Critical and fourteen rated High severity,…

  • Anthropic Accuses Alibaba of ‘Illicitly’ Accessing Its Claude AI Models in Largest Known Distillation Attack

    Anthropic Accuses Alibaba of ‘Illicitly’ Accessing Its Claude AI Models in Largest Known Distillation Attack Anthropic has formally accused Chinese tech and e-commerce giant Alibaba of orchestrating a massive, unauthorized extraction campaign targeting its Claude AI model, marking what the company describes as the largest known distillation attack in its history. In a letter dated…

  • Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection

    Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint security components. This clever camouflage helps it avoid detection, allowing attackers to maintain a persistent, low-profile foothold…

  • Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents

    Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents A malicious AI “skill” created as part of a controlled security experiment has exposed critical weaknesses in modern AI agent ecosystems, successfully bypassing security scanners and compromising more than 26,000 agents across individual and enterprise environments. According to researcher Niv…

  • Claude Fable 5 Wrote Windows Kernel Code in Rust in 38 Minutes

    Claude Fable 5 Wrote Windows Kernel Code in Rust in 38 Minutes Anthropic’s Claude Fable 5 generated a complete, bootable NT-compatible Windows kernel written in Rust called ntoskrnl-rs from an empty directory in just 38 minutes of active model work, raising profound questions about AI-authored trust and the future of critical infrastructure security. Documented by…

  • GTA 6 Scam Websites Use AI-Generated Images and Fake Download Buttons to Lure Gamers

    GTA 6 Scam Websites Use AI-Generated Images and Fake Download Buttons to Lure Gamers A fresh wave of scam websites is targeting gamers worldwide, using the massive hype around Grand Theft Auto VI to trick people into handing over their money. These fake pages promise something millions of players desperately want: early access to GTA…

  • FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials

    FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials A large-scale, ongoing credential-harvesting campaign dubbed “FortiBleed” has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since at least February 2026. The campaign came to light after security researcher Volodymyr “Bob” Diachenko discovered an exposed directory…

  • How Attackers Exploit Privileged Access and How to Lock Them Out 

    How Attackers Exploit Privileged Access and How to Lock Them Out  Every major breach you read about has a quiet middle chapter that rarely makes the headline. The headline is the ransom note or the leaked customer database. The middle chapter the part that actually decided the outcome is almost always the same: an attacker found a privileged credential, used it…

  • Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability

    Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability A researcher has earned a total of 148,337 USD from Google for uncovering a set of flaws in Google Cloud’s Application Integration service that escalated into remote code execution (RCE) in Google Cloud production. The core bug is now tracked as CVE‑2026‑2031. The researcher Arvin Shivram…

  • Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents

    Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents Indian electronics manufacturing giant Tata Electronics confirmed a “cybersecurity incident” on Monday after ransomware group World Leaks published over 200,000 files totaling more than 630 gigabytes on the dark web, allegedly containing proprietary and confidential documents belonging to Apple and Tesla. World Leaks, a ransomware…

  • New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users

    New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users Phishing attacks have grown more sophisticated, and attackers are no longer relying on clunky fake emails or obvious scam messages. A newly identified campaign shows how threat actors are turning everyday Microsoft 365 tools into weapons, hiding their attacks inside the very…

  • Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets

    Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets A critical security vulnerability has been identified in the widely used libssh2 library, allowing remote attackers to execute arbitrary code through specially crafted SSH packets. The flaw, tracked as CVE-2026-55200, carries a CVSS score of 9.2 and is classified under CWE-680 (Integer…

  • Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files

    Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files A critical vulnerability has been disclosed in FFmpeg’s MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in some scenarios, achieve remote code execution (RCE). The flaw, tracked as CVE-2026-8461 and dubbed “PixelSmash,” is a heap out-of-bounds write in FFmpeg’s libavcodec component, with…

  • Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations

    Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations China’s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry…

  • North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines

    North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines North Korean hackers have turned a widely used developer tool into a weapon, quietly poisoning more than 140 software packages that developers across the world rely on every day. The campaign is sophisticated, stealthy, and far-reaching, raising urgent questions about the…

  • 13-Word Reddit Comment Can Poison ChatGPT and Gemini AI Search Results

    13-Word Reddit Comment Can Poison ChatGPT and Gemini AI Search Results A newly published academic paper has revealed a critical vulnerability in AI-powered deep-research systems, including those underpinning commercial tools like OpenAI’s Deep Research and Google’s Gemini Deep Research, that allows a single short Reddit comment to manipulate the reports these agents generate for thousands…

  • Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware

    Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware Hackers are using fake Google Ads to push a brand-new malware loader that disguises itself as the popular Node.js installer. The campaign has been actively targeting Windows users in the United States, silently dropping a dangerous infostealer onto their machines after just a single…

  • Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script

    Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script A large-scale malware campaign has been uncovered on GitHub after a researcher identified more than 10,000 repositories distributing Trojan-laced archives, raising concerns about abuse of the platform’s trust model and limitations in automated detection. The investigation began when the researcher noticed a cloned version of their…

  • GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes

    GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware…

  • CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT

    CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT A new open-source cybersecurity platform called CyberSentinel AI v3.0 has emerged as a significant development in autonomous security tooling, combining 33 real-world penetration testing and threat intelligence tools with a provider-agnostic AI engine that supports Claude, GPT-4o, OpenRouter, and fully offline…

  • AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code

    AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and execute arbitrary code on the host machine without any user interaction beyond submitting a URL. AutoJack is a three-vulnerability…

  • CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation

    CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw affects shared hosting environments and poses a significant risk to servers running CloudLinux with…

  • Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers

    Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and potentially access sensitive data across websites and local systems. Security researchers at Rebora Security uncovered vulnerabilities dubbed…

  • Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

    Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1,…

  • China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies

    China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies A sophisticated China-linked malware framework has been quietly targeting telecom companies across the Middle East for nearly four years. Showboat is a Linux-based tool that stayed completely hidden from antivirus systems until April 2026, raising serious concerns about the security of critical communications infrastructure worldwide.…

  • CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks

    CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks CISA has issued a high-priority alert warning organizations about a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild. The flaw, tracked as CVE-2026-20253, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling immediate risk to enterprise…

  • Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses

    Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses Node.js has released a new round of security updates addressing 12 vulnerabilities across its supported release lines, including two high-severity flaws that could lead to authentication bypass and denial-of-service (DoS) attacks. The updates impact Node.js versions 22.x, 24.x, and 26.x, with patched releases now available as…

  • Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives

    Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. The malware is not just a simple thief. It…

  • AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring

    AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring Governments are expanding their digital reach in ways unimaginable just a decade ago. A growing wave of AI-powered surveillance, biometric data collection, and commercial spyware is reshaping how states monitor citizens and visitors. The scale of this shift is drawing urgent attention from security professionals…

  • Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch

    Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed “RoguePlanet,” and confirmed it is actively developing a security patch to address the flaw. Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response…

  • Google Cloud Vertex AI Allows Attacker to Hijack Victim’s Model and Poison it

    Google Cloud Vertex AI Allows Attacker to Hijack Victim’s Model and Poison it A newly disclosed vulnerability in Google Cloud Vertex AI could have allowed attackers to hijack machine learning model uploads and execute malicious code in victim environments, according to research shared with Google under responsible disclosure. The issue affects the Vertex AI Python…

  • GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions

    GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions A sophisticated phishing campaign called “GitBait” has been caught targeting Mexico’s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that look nearly identical to the…

  • Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility

    Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility Threat actors are increasingly targeting cloud logging services to evade detection and maintain persistent visibility into compromised environments, according to recent research by Palo Alto Networks Unit 42. These services, designed as a critical security layer, are now being weaponized to create blind spots…

  • AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox

    AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox AIRecon is an autonomous penetration testing agent that runs entirely offline, combining a self-hosted Ollama LLM with a Kali Linux Docker sandbox to automate end-to-end security assessments without exposing any data to the cloud. Developed by researcher pikpikcu, it eliminates the prohibitive cost of commercial API-based…

  • Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection

    Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows attackers to bypass authentication mechanisms under specific conditions by exploiting improper handling of the Host header. The issue…

  • Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!

    Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now! Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users are strongly advised to update immediately as several flaws impact core browser components. The latest Chrome…

  • Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices

    Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices A newly discovered Android banking trojan called Rokarolla is making waves in the cybersecurity world, and it is more dangerous than most threats we have seen lately. This malware is built to take full control of an infected device while staying completely…

  • Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees

    Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees A new strain of malware has emerged that combines two well-known social engineering tactics into one effective attack chain. Researchers have uncovered a Remote Access Trojan built on Deno, an unconventional JavaScript runtime, being deployed against employees through email flooding and fake Microsoft Teams…

  • OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack

    OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec discovered an ongoing campaign targeting plugins developed…

  • Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen

    Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen The global ransomware landscape shifted noticeably in the first quarter of 2026, as former operators from well-known criminal groups began launching their own competing programs. Data leak sites tracked 2,122 new victims during Q1 2026, making it the second-highest first-quarter total on record. Despite…

  • Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns

    Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns A wave of phishing campaigns targeting American taxpayers has been traced back to a single, highly organized cybercrime operation known as The Quarry. What appeared to be dozens of unrelated incidents impersonating the IRS, Social Security Administration, and platforms like DocuSign turned…

  • LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild

    LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited in the wild, posing a serious threat to shared hosting environments worldwide. The flaw, tracked as CVE-2026-54420, enables privilege escalation to root level, allowing attackers to take full control of affected…

  • Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks

    Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise network environments worldwide. The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a…

  • SecSuite – AI-powered Tool for OSINT, Web and API Security Testing

    SecSuite – AI-powered Tool for OSINT, Web and API Security Testing A new open-source security platform called SecSuite, developed under the TheSecuredAnalyst project, has been released, combining OSINT reconnaissance, web vulnerability scanning, API security assessment, compliance checking, and AI-powered analysis into a single unified toolkit. Available on GitHub at 53cur3dL34rn/security-suite, the tool targets security professionals, penetration testers, and red…

  • WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer

    WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer Russian hackers are exploiting a known flaw in WinRAR to quietly steal passwords, session cookies, and sensitive files from Ukrainian organizations. The vulnerability, tracked as CVE-2025-8088, was patched in July 2025, yet multiple Russia-aligned groups are still weaponizing it nearly a year later. This proves…

  • Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild

    Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Palo Alto Networks Unit 42 has issued an urgent warning about active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS software. The flaw allows unauthenticated remote attackers to circumvent security controls and initiate unauthorized…

  • Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page

    Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page A misconfigured PHP installation page exposed the internal infrastructure of a live malware distribution platform, allowing a security researcher to gain unintentional administrative access to a threat actor’s dashboard. What initially appeared to be a fake software download site turned out to be an active…

  • Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings

    Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings The Office of the Maine Attorney General has temporarily taken its public-facing data breach reporting database offline after discovering that an unknown entity submitted fabricated breach notifications targeting two major online platforms, VRChat and Discord, in what officials are calling a deliberate…

  • 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic

    152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic 152 Chrome “live wallpaper” extensions on the Chrome Web Store have been caught secretly logging user data and faking Google “organic search” traffic to inflate ad revenue, despite promising they do not collect any data. This adware‑adjacent campaign abuses new‑tab extensions to launder extension‑generated…

  • New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From a Hacker’s Server

    New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From a Hacker’s Server New “Agentjacking” attack that hijacks AI coding agents and silently executes attacker-controlled code on developer machines using nothing more than a single injected Sentry error. The technique turns trusted AI assistants like Claude Code and Cursor into an execution layer…

  • BugHunter – Bug Bounty Toolkit Powered by Claude and Free AI Providers

    BugHunter – Bug Bounty Toolkit Powered by Claude and Free AI Providers A new open-source bug bounty hunting toolkit called BugHunter, built on top of Anthropic’s Claude Code and now extended to support free AI providers like Ollama and Groq, is gaining traction in the security research community for automating the full vulnerability discovery and…

  • Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication

    Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication A critical vulnerability chain in Splunk Enterprise has been disclosed, enabling unauthenticated attackers to achieve remote code execution (RCE) through a misconfigured PostgreSQL sidecar service. Tracked as CVE-2026-20253, the flaw has a CVSS score of 9.8 and affects Splunk Enterprise 10 and later. The issue…

  • Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive

    Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Anthropic has disabled its two most capable AI models, Fable 5 and Mythos 5, after the U.S. government issued an export control directive late on June 12 ordering the company to block access for any foreign national, whether inside or outside…

  • Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks

    Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as Fancy Bear, formally tracked as APT28 and attributed to Russia’s military intelligence unit GRU Unit 26165, has been quietly shifting…

  • Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection

    Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection A newly documented phishing campaign is using a legitimate remote management tool to silently take over victims’ computers, without deploying a single line of traditional malware. Researchers have uncovered an active operation targeting Brazilian organizations, where attackers trick employees into installing a real enterprise…

  • Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets

    Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets the moment…

  • Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications

    Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications A new and dangerous credential-stealing tool called OnyxC2 has emerged in the cybercrime underground, showing just how easy it has become for even low-skilled attackers to run a professional hacking operation. Sold as a complete package for $250 a month, the malware gives buyers everything…

  • Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code

    Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Microsoft released critical fixes for three closely related remote code execution (RCE) vulnerabilities in Microsoft Outlook and Word that stem from low‑level memory‑safety flaws in the Word rendering engine and its integration with Outlook Classic. These bugs, tracked as CVE‑2026‑45456, CVE‑2026‑45458, and CVE‑2026‑47635, are…

  • Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User

    Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Palo Alto Networks fixed a new command injection vulnerability in PAN‑OS (CVE-2026-0273) that allows authenticated administrators to execute arbitrary commands as root via the CLI or web management interface. Two related medium‑severity issues in the same advisory window cover CLI privilege escalation…

  • Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code

    Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Google has released a new Chrome security update addressing 28 vulnerabilities, including several critical flaws that could allow attackers to execute malicious code on affected systems. The latest Stable channel update upgrades Chrome to version 149.0.7827.114/.115 on Windows and macOS, and to 149.0.7827.114…

  • Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data

    Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Microsoft has disclosed a significant security vulnerability in Microsoft Teams for Android that could allow an authenticated attacker to expose sensitive information over a network. The flaw, tracked as CVE-2026-42835, was officially released on June 9, 2026, and has been rated Important in severity.…

  • Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters

    Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters Mandiant and Google Threat Intelligence Group (GTIG) have issued a critical warning after identifying an active compromise-and-extortion campaign targeting Oracle PeopleSoft infrastructure, attributed to the notorious threat actor UNC6240, also known as ShinyHunters. The campaign exploited CVE-2026-35273, a critical unauthenticated remote code execution (RCE) vulnerability…

  • China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation

    China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls more than…

  • Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email

    Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email Microsoft has confirmed active exploitation of a new zero‑day spoofing flaw in on‑premises Exchange Server, tracked as CVE‑2026‑42897. The flaw allows attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) simply by sending a weaponized email that a victim opens in a browser.…

  • Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks

    Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks A high-severity vulnerability, CVE-2026-6973, in Ivanti Endpoint Manager Mobile (EPMM) could allow authenticated attackers to achieve remote code execution by injecting malicious Apache configuration directives. The flaw, assigned a CVSS score of 7.2, is classified as a configuration control vulnerability (CWE-15) and affects multiple versions…

  • Anthropic’s Claude Fable 5 Jailbroken to Generate Stack Exploits

    Anthropic’s Claude Fable 5 Jailbroken to Generate Stack Exploits Anthropic launched Claude Fable 5 on June 9, 2026, as the first publicly available model in its new Mythos class, its most capable AI to date, excelling in software engineering, knowledge work, and vision benchmarks. Researcher “Pliny the Liberator” defeats Claude Fable 5’s safety classifiers using…

  • Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency

    Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency Hackers are turning everyday software searches into a trap. A sophisticated cryptojacking campaign is actively targeting users who search for popular PC utilities online, luring them into downloading malware-laced files that secretly mine cryptocurrency using their own GPU. The attackers have built a network…

  • Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain

    Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain A newly discovered backdoor malware called MLTBackdoor is making waves in the cybersecurity community after being spotted in a carefully designed, multi-stage attack chain. Identified in May 2026, this threat stands out for its advanced ability to hide from security tools while quietly establishing a deep…

  • Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials

    Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials Cybercriminals are now turning to short-form video platforms as a new attack surface, using fake software tutorials on TikTok and Instagram Reels to push malware onto unsuspecting users. The tactic is simple but remarkably effective: create polished, convincing videos that promise…

  • Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature

    Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature Microsoft disclosed a new Windows BitLocker Security Feature Bypass vulnerability, tracked as CVE-2026-50507, on June 9, 2026, as part of its June Patch Tuesday security release. The flaw, rooted in a protection mechanism failure, allows an unauthorized attacker with physical access to bypass BitLocker Device Encryption…

  • Anthropic Released Claude Fable 5, the First Model in Mythos Class

    Anthropic Released Claude Fable 5, the First Model in Mythos Class Anthropic has released Claude Fable 5, the first publicly available model in its new Mythos capability tier, a class powerful enough that the company says it ships with cybersecurity safeguards baked in from day one. Fable 5 sits above the Claude Opus line and…

  • New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers

    New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers A researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse or Dead Eclipse) has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet, targeting a previously undisclosed race condition vulnerability in Microsoft Windows Defender. When successfully executed, the exploit spawns a command shell…

  • Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands

    Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands Threat actors are actively exploiting a critical chained vulnerability in LiteLLM, a popular open-source AI gateway proxy, allowing unauthenticated remote code execution (RCE) on vulnerable deployments. Researchers at Horizon3.ai confirmed that combining two CVEs creates a CVSS 10.0 Critical attack path requiring zero…

  • SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched

    SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched SAP’s June 2026 Security Patch Day, observed on Tuesday, June 9, delivered 15 new security notes addressing a broad range of vulnerabilities across core SAP products, including four critical-severity flaws that demand immediate enterprise attention. SAP strongly urges all customers to visit the SAP…

  • Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

    Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials Cybercriminals have found a clever new trick: turning the world’s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials, credit…

  • Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws

    Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, heap-based buffer overflows, denial-of-service, privilege escalation, and out-of-bounds read issues affecting…

  • 21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks

    21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks An autonomous security agent uncovered 21 zero-day vulnerabilities in FFmpeg, the world’s most widely deployed media processing library, including a critical RCE-capable heap buffer overflow reachable with a single 183-byte network packet. FFmpeg quietly powers media processing across browsers, streaming platforms, surveillance systems, and cloud…

  • Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

    Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in…

  • UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials

    UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root access to affected devices without a single credential, turning one unauthenticated request into a complete system takeover.…

  • Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

    Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic directly in the…

  • Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams

    Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams The 2026 FIFA World Cup is not just a celebration of football. For cybercriminals, it is a business opportunity, and they have already gotten to work. Threat actors have been building fake FIFA stores, spinning up phishing pages, and launching purchase scams…

  • Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets

    Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for attackers. A recently uncovered vulnerability in a widely used AI coding assistant shows just how far that…

  • Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

    Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg and model Georgina Rodriguez. Instagram’s parent…

  • CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

    CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The issue, categorized as improper authentication, affects Linux…

  • New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks

    New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks OpenAI has released ChatGPT Lockdown Mode, a new security feature designed to limit outbound network access and reduce the risk of data exfiltration from prompt-injection attacks. The feature is now available to eligible personal accounts, self-serve ChatGPT Business users, and managed enterprise workspaces.…

  • Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies

    Free Apps on Samsung and LG Smart TVs Secretly Turning Your Devices Into AI Proxies Free apps available on Samsung, LG, Roku, and other major smart TV platforms have been quietly enrolling millions of living room devices into a commercial residential proxy network used to scrape web data for AI training all through a consent…

  • CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

    CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, the vulnerability affects SolarWinds Serv-U file transfer software and…

  • Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks

    Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks A newly disclosed critical vulnerability in the HuggingFace Transformers library, tracked as CVE-2026-4372, allows attackers to achieve remote code execution (RCE) through malicious model configuration files. The flaw exposes a significant supply chain risk in one of the most widely used machine learning frameworks, impacting…

  • OWASP CVE Lite CLI – New Tool to Scan for Vulnerabilities in Your Projects

    OWASP CVE Lite CLI – New Tool to Scan for Vulnerabilities in Your Projects CVE Lite CLI is a free, open-source vulnerability scanner officially recognized as an OWASP Incubator Project, designed to bring dependency security directly into developers’ terminals rather than leaving it buried in CI pipelines. Maintained by Sonu Kapoor and backed by the…

  • VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore

    VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, the attacker’s own decryptor may not fully restore their files. This is not a typical failure…

  • Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

    Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and stems…

  • Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats

    Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats Let’s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without bloating TLS handshakes or breaking the web’s performance expectations. Traditional X.509 certificate chains require significant…

  • Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code

    Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw carries a CVSS v3 score of 7.5 and…

  • Dashlane Details How Hackers Managed to Download Encrypted Password Vaults

    Dashlane Details How Hackers Managed to Download Encrypted Password Vaults Dashlane has disclosed that threat actors successfully brute-forced two-factor authentication (2FA) protections to register unauthorized devices and download encrypted password vaults belonging to fewer than 20 personal plan users, with a completed investigation confirming no broader impact on its internal systems. Beginning Sunday, May 31,…

  • Acer Working to Patch Wave 7 Router 0-day Vulnerability

    Acer Working to Patch Wave 7 Router 0-day Vulnerability Acer is preparing a firmware update to address a critical zero-day vulnerability affecting its Wave 7 routers, following disclosure by independent security researcher Gergo Pap. The issue affects devices running firmware versions earlier than and poses a significant risk due to unauthenticated remote exploitation. According to…