ModernStealer is the name behind underground posts claiming to offer military, government, nuclear, and aerospace material. The posts appeared on dark web…
Category: Cyber Security News
XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands
XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a…
Internet-Facing SonicWall SMA Appliances Face Zero-Click Root Compromise
Internet-facing SonicWall Secure Mobile Access, or SMA, appliances face a serious threat after attackers turned two flaws into a route to full VPN-gateway…
Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft
A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised…
Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated…
MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets
Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a…
Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 Stories
AI systems moved from experimental risk to confirmed attacker, a Cisco firewall zero-day was actively exploited in the wild, and a critical VMware…
SplitVPN Data Breach Exposes 865k Users’ Personal Records
A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique…
Brinks Home Confirms Data Breach Following ShinyHunters Claim
Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious…
Top 10 Best DNS Security Solutions in 2026
Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break…
Top 10 Best Web Application Firewall (WAF) in 2026
A web application firewall (WAF) filters malicious HTTP/S traffic SQL injection, cross-site scripting, credential stuffing, and API abuse — before it…
Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress
Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and…
Top 10 Best Cloud Firewall Solutions in 2026
Cloud workloads don’t sit behind your data-center firewall, and attackers know it. A cloud firewall inspects and controls traffic to, from, and between…
Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network
Adform, a major advertising technology company serving roughly 14,000 businesses and holding nearly 30% of the demand-side platform market, has suffered a…
Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits
Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and…
HackerOne Mandates ID Verification for Bug Bounty Submissions
HackerOne has confirmed that all hackers must now complete identity verification before submitting reports to any bug bounty program (BBP) on its…
CyberStrike – AI-Powered Security Platform for Automated Penetration Testing
A new open-source project called CyberStrike is positioning itself as the first AI agent built specifically for offensive security, turning any existing…
Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other…
Your Incident Response Plan Has a Dependency You Never Approved
During the first publicly documented agent-driven intrusion, the defenders tried to analyze the attack with commercial AI models and were refused. The…
Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login
SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.…