Every industrial organisation now lets someone in from the outside — OEM vendors, system integrators, remote engineers. How they get in determines whether…
Category: Cyber Security News
WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks
A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress…
Malicious Apache Modules Turn Trusted Government Websites Into Stealth Phishing Proxies
Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious…
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take…
Claude AI Now Controls Your macOS and Windows Computer in the Background
Anthropic has quietly pushed one of its most consequential agentic upgrades yet, letting Claude take control of a user’s desktop and complete tasks while…
OpenMatter Network Expands Platform with New Capabilities for Secure AI, Computing and Data Collaboration
Melbourne, Florida, September 2nd, 2026, CyberNewswire Less than three months after its commercial launch, OpenMatter Network today announced a…
WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos
A newly disclosed WhatsApp flaw on Android is raising fresh privacy alarms, allowing anyone holding a locked phone to browse through its entire photo…
Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse
A wave of cyberattacks across the US and Europe in August exploited the trust businesses place in everyday tools, turning Microsoft 365 logins,…
Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities
Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is…
GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok
A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer’s machine the…
Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw
Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID…
Firefox on iPhone Can Now Block Ads and Trackers Without Installing an Extension
Mozilla has introduced a built-in Ad Blocker for Firefox on iOS, allowing iPhone users to block many third-party advertisements and ad-related trackers…
Authorities Disrupted 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems
The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims…
BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers
Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as…
Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC
A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide.…
Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and…
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk…
FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users…
Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers
Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full…
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI…