A newly disclosed AI attack technique shows that harmful commands do not need strange symbols, hidden text, or coded strings to evade security checks.…
Category: Cyber Security News
Harley-Davidson Alleged Breach – CL0P Ransomware Adds Motorcycle Maker to the List
The CL0P ransomware operation has allegedly added iconic motorcycle manufacturer Harley-Davidson to its public leak site, claiming it compromised the…
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone
A security vulnerability in Skullcandy Dime 3 wireless earbuds could allow nearby attackers to pair with the device without the owner’s approval, hijack…
Remote Desktop Services Failures on Windows Servers Following September Update
Windows administrators worldwide are grappling with a disruptive Remote Desktop Services (RDS) bug that surfaced immediately after Microsoft shipped its…
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection
Anthropic’s Threat Intelligence team has disclosed a sweeping new report detailing how state-sponsored espionage groups, financially motivated…
Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models
Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a…
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign…
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use…
CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing…
Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with…
Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a…
WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding…
OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities
OpenAI has introduced a “Defense Factory,” an automated, agent-first cybersecurity operation that continuously discovers, validates, and remediates…
Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User
Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with…
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS…
Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes
Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.…
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited…
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography
The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run…
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a…