Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF…
Category: Cyber Security News
OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign
OpenAI has removed a cluster of ChatGPT accounts linked to a covert influence operation from Russia. The accounts produced social-media posts and replies…
Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels
Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied to Tortoiseshell,…
Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware
Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access…
24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages
Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The campaign does not…
WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks
A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully…
Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access
A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems. The campaign uses…
SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root
SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow an…
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The…
NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit
A critical vulnerability in NVIDIA NemoClaw that could let attackers hijack an AI agent after a victim visits a malicious website. The issue, tracked as…
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno…
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States…
Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10 critical…
28,000 Exposed Git Repositories Reveal API Keys, Bank Details and Employee Disciplinary Files
A routine development mistake has exposed thousands of software repositories. Researchers found 28,000 publicly reachable .git repositories containing…
New CoreRAT Malware Gives Core Werewolf Hackers Full Control of Compromised Systems
A new remote access trojan called CoreRAT is giving the Core Werewolf threat group a way to take over infected Windows systems. The malware appeared in…
Linux Turns 35 – Hobby Kernel Now Powers Cloud, Android, and Global Cyber Defense
On August 25, 1991, a 21-year-old University of Helsinki student posted a modest note to the Usenet group comp.os.minix. “I’m doing a (free) operating…
Microsoft Teams Outage Largely Mitigated After Users Lost Access to Multiple Features
Microsoft confirmed early Wednesday that customers may have been unable to use multiple Microsoft Teams features, then said its monitoring showed the…
Multiple OpenSSL Flaws Let Remote Attackers Crash Servers and Corrupt Heap Memory
OpenSSL has issued a fresh security advisory disclosing seven vulnerabilities across its cryptographic library, ranging from a heap-corrupting write bug…
CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps
CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is…
AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a $140 million funding round led by Apax Digital Funds, with…