Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was…
Category: Cyber Security News
Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix
Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked…
Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack
Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion. The…
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote…
Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment
Proactive AI-native security vendor Horizon3 has announced a major $20 million investment into its global partner ecosystem. The funding reinforces the…
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July…
New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines
A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings,…
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open…
LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident…
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being…
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter…
New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp
A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
New Phishing Attack Leverage SSL/TLS Certificates to Target High-value Brands Customers Via Whatsapp
A phishing operation is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition
Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning…
Anthropic to Add Invisible Watermarks to All Claude AI Outputs
Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company’s decision to…
OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming
OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue…
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security…
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s…
Claude Code Shifts Agent Security From Repeated Human Approval to Auto Mode
Anthropic is changing how Claude Code handles risky commands, moving away from constant human approval prompts and toward an automated safety classifier…
HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys
A security researcher has disclosed a boot-chain weakness in HP ThinPro 8 and 9 that could allow attackers with physical access to a thin client to…
