A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an…
Category: Cyber Security News
AWS Network Firewall Now Displays Count of Triggered Security Rules
AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are…
New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File
A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service.…
Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories
This week’s bulletin captures a cybersecurity landscape increasingly shaped by artificial intelligence, both as a weapon and a shield. A ransomware…
Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack
A cyberattack attributed to hackers linked to Iran forced a British power plant offline for four consecutive days last month, marking what officials…
Microsoft Windows 11 App Pushes Bing as Default Search in Chrome, Firefox and Brave
Microsoft has built a dedicated Windows 11 app that exists to put Bing in front of users who already chose another search engine. The utility, Microsoft…
Top 10 Best Wireless / Wi-Fi Security Solutions in 2026
Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions, combining cloud-managed simplicity with strong policy…
What specifically allowed the agent to reach a real company’s systems during testing?
Wayne Anderson, Managing Director, Cybersecurity and Digital Innovation, BDO USA. First and foremost, the technical “walls” were reduced during the…
Grok Zero-Click Attack Steals Chat Data Using Encrypted Prompt Injection
A newly disclosed attack can turn a routine “summarize this page” request in xAI’s Grok web chat into a silent theft of the user’s name, coarse location,…
What 45 Million wp2shell Exploit Attempts Reveal About the New Vulnerability Response Window
The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that…
Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users
Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users…
Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning
Anthropic has expanded access to its frontier AI cyber-defense capabilities by making Claude Mythos 5 available in Claude Security, enabling enterprise…
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal…
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical…
US Bank Investigating Data Breach Following LockBit Ransomware Claim
US Bank is investigating LockBit’s claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on…
Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection
Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing…
Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks
Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a…
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on…
Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The…
Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more…