ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text,…
Category: Cyber Security News
SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route for malware delivery. The campaign relies on…
WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless…
Microsoft August 2026 Update Breaks When Generating PDF/XPS Content
Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in Windows…
91 Spring Vulnerabilities Impact 209,000+ Software Components Across Open-Source Ecosystem
Broadcom has released a major batch of Spring security advisories, with Sonatype tracking 91 CVEs across Spring Framework and related projects. The August…
Multiple Zscaler Client Connector Vulnerabilities Enable RCE Attacks
Multiple vulnerabilities affecting Zscaler Client Connector have been disclosed, potentially allowing remote code execution on vulnerable systems. Tracked…
ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer
ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages,…
Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over…
ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed…
Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers.…
Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more…
AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting
AliExpress’s homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears to power an aggressive…
EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next
EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised…
Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages
Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets…
Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts
Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any…
Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary…
CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the…
Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors
Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that…
Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions
A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns…
Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds
Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search…