Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks. This criminal technique uses malware to…
Category: Cyber Security News
Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations
Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and…
Hackers Hide RevStealer Inside Fake Claude Opus 5 App to Steal Passwords and Crypto
Hackers are using a fake Claude Opus 5 desktop application to distribute RevStealer, a Windows malware built to take passwords, browser data and…
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication…
New Windows Backdoor Stays Completely Silent Until Hackers Send a Secret Trigger
SLEEPWALKER is a newly identified Windows backdoor built to wait rather than call home. Once placed on a compromised device, it can sit inactive for an…
Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones
Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft. The campaign hides…
Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack
A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with…
Hackers Compromise Cisco Routers to Spy on Networks and Reach Critical Infrastructure
Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage…
Hackers Target AWS Root Accounts at 150+ Organizations in Password-Spraying Campaign
Datadog Security Research observed a password-spraying campaign targeting AWS root accounts at more than 150 organizations between July 24 and August 23,…
BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update
Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a…
Anthropic Hardens Claude Security After AI Models Gain Unauthorized Access to Real Systems
Anthropic has hardened security around its Claude models after several incidents in which the systems gained unauthorized access to real computers during…
CISA Warns of Multiple PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its Known…
Microsoft Investigating New Exchange Online Outage Tracked as EX1464935 [Updated]
Microsoft has opened an active investigation into a new Exchange Online disruption after a wave of user reports flagged access and mail-flow problems…
Broadcom Launches VMware AI Factory to Secure Enterprise AI Agents
Broadcom unveiled VMware AI Factory at VMware Explore 2026 in Las Vegas, introducing a software-defined foundation within VMware Private AI Cloud designed…
HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the…
D-Link Router Flaws Let Unauthenticated Attackers Change Admin Password and Steal Wi-Fi Credentials
D-Link has released a firmware update for critical access-control and information-disclosure flaws affecting its DIR-X1860Z router. The vulnerabilities…
Android 17 Adds New Protection for Wi-Fi Tracking to Keep Your Device Secure
Google has introduced new privacy and network-security protections in Android 17, including stricter controls that prevent apps from scanning devices…
19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords
Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data. The extensions…
Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm
A widely used npm package has become a credential-stealing delivery channel after attackers planted a self-spreading Shai-Hulud payload in its releases.…
EU Designates ChatGPT as Very Large Online Search Engine After Crossing 45 Million Users
The European Commission on Monday designated OpenAI’s ChatGPT as a Very Large Online Search Engine under the Digital Services Act, after the chatbot…