Meta has launched Muse Image, its first image generation model built by Meta Superintelligence Labs, and the release has already triggered a privacy backlash because it lets users pull public Instagram photos into AI-generated visuals without notifying the account owner.…
Category: Cyber Security News
New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware
A newly disclosed attack technique dubbed “HalluSquatting” is raising serious concerns in the cybersecurity community after researchers demonstrated how AI coding assistants can be manipulated into installing botnet malware through hallucinated resources. The research, conducted by Aya Spira, Stav Cohen,…
GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise Editions
GitLab has released critical security updates addressing eight vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), urging users to upgrade immediately to mitigate potential risks. The latest patch versions 19.1.2, 19.0.4, and 18.11.7 were published on July 8,…
Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability
Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on…
Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data
Helix has surfaced as a fast-moving data extortion group that targets Microsoft 365 users through phone scams and cloud-focused phishing instead of traditional malware drops. Attackers are after access first, then large volumes of corporate files, with SharePoint libraries becoming…
Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic
Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending specially crafted network traffic. Tracked as CVE-2026-0288, the flaw carries a CVSS-B score…
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass…
Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code
IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. A threat actor operating under the alias…
Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers
AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections tied to credential access and living-off-the-land binaries (LOLBins). Recent analysis from Sophos’ CIXA…
APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor
A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides shellcode inside PNG images to…
PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution
A newly identified strain of Android spyware called PromptSpy has become the first mobile malware known to call on generative AI while it is actually running on a victim’s device. Rather than relying purely on hardcoded commands, the malware reaches…
ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers
A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed to copy and…
Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes
A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to…
DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists
DuckDuckGo has rolled out native YouTube ad blocking across its browser applications, automatically stripping pre-roll and mid-roll video ads without requiring users to install third-party extensions. The feature works across YouTube and other video platforms, marking a significant shift in…
Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain
A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the…
Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service
A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework,…
AI Double Agent Attack Turns Claude Desktop to Execute Remote Code on a Target Machine
A compromised email inbox can be weaponized into full remote code execution on a victim’s machine, not through malware or phishing links, but by turning the victim’s own Claude Desktop assistant against them. The attack uncovered by Security researchers at…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability
Proof-of-concept (PoC) exploit code and deep technical details have now been released for CVE-2025-53770, a critical remote code execution (RCE) vulnerability in on‑premises Microsoft SharePoint Server. This disclosure raises the risk of rapid weaponization and mass exploitation against unpatched SharePoint…
First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone
A full-chain exploit dubbed “IonStack” demonstrates how a single malicious URL click can hand attackers complete control over an Android device. The proof-of-concept by Nebula Security, described as the world’s first public Android 17 root demo, chains two zero-day vulnerabilities…
Hackers Exploit Roundcube N-Day Flaws to Steal Credentials and Deploy VShell
A newly identified hacking campaign is targeting university mail servers by exploiting known but unpatched flaws in Roundcube webmail software. The attackers are using these gaps to quietly steal login credentials and plant a powerful backdoor called VShell deep inside…