TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The…
Category: Cyber Security News
Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect VPN
A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint…
Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect
A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint…
Kimsuky Uses AI-Generated Chrome Extension to Automatically Steal Gmail Data
Kimsuky has been linked to a new espionage campaign that turns a Chrome extension into a quiet Gmail collector. The operation begins with convincing…
WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover…
768 Leaked Corporate AWS Keys Remain Active With Full Administrator Access
A new cloud security investigation from Truffle Security has found that 768 publicly exposed AWS credentials still provide full administrative control…
Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild
CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration…
Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots
Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams…
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message. Criminals are manipulating…
New Mysterious AI Model Dubbed Ox Alpha With Free 100 Trillion Tokens a Day for Coders
A mysterious AI system named Ox Alpha has sparked intense speculation across the developer community after appearing on OpenRouter as a free “stealth…
Hackers Impersonate ReliaQuest Security Team Member to Steal SSO Credentials and MFA Access
ReliaQuest has disclosed a social engineering attack in which threat actors impersonated members of its security team to lure employees to a fraudulent…
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
AmnesiaStealer is a newly identified macOS information stealer that does more than copy saved passwords. It can give criminals quiet control of a browser…
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader. The campaign relies on a familiar…
Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features
Microsoft is investigating a Windows 11 issue in which the August 2026 security updates can cause certain games to freeze, crash, display access-violation…
Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto
Mac users are being lured into a ClickFix campaign that turns a routine CAPTCHA check into a path for password theft, remote control, and cryptocurrency…
Anthropic’s Claude AI Suffers Another Outage With Elevated Errors
Anthropic’s Claude AI platform experienced another wave of elevated errors on August 24, 2026, marking yet another disruption in what has become a…
Hackers Infect Android Car Screens Through Their Built-In Software Update System
A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target. Rather than tricking drivers into installing a…
Hugging Face Reportedly Explores $13 Billion Sale Following Recent AI Security Incident
Hugging Face is testing a sale that could value the open-source AI hub at $13 billion or more, even as it is still closing out July’s autonomous-agent…
Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution
A critical security flaw in the popular Node.js sandboxing library isolated-vm could allow untrusted JavaScript to escape its V8 sandbox and potentially…
Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks
Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date…