WhatsApp is developing a new privacy control called Restricted Chat that will keep selected conversations accessible only from a user’s primary mobile…
Category: Cyber Security News
Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on,…
Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall…
New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control.…
AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions
A critical vulnerability in the AWS Systems Manager Agent could let authenticated attackers bypass remote-host port-forwarding restrictions and access…
Hackers Leverage Claude to Exfiltrate Secrets from 1.8M Android apps
Cybercriminals linked to the ShinyHunters ecosystem used Claude to support a large-scale credential theft operation that downloaded, decompiled, and…
Microsoft Confirms Remote Desktop Services Might Stop Working Following Sept. 2026 Security Update
Microsoft has confirmed that its September 2026 Windows security updates can destabilize Remote Desktop Services (RDS), potentially disrupting remote…
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution…
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation…
Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices. The campaign uses…
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process. The campaign starts with a…
NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it…
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE…
Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system
Dell Technologies released a security advisory about multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deployments.…
Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers
Revolut has disclosed a data-security incident in which sensitive customer information was released after the financial technology company received a…
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected…
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The…
Containing Machine Speed Cyber Attacks Inside AI Infrastructure
A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response…
Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks
A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May…
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation…