RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira,…
Category: Cyber Security News
Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results…
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent…
Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts
Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than…
Claude-Powered OpenClaw AI Agent Exploits Gym API to Steal a Workout Slot
An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it…
Microsoft to Launch New Security Detection Report in Teams
Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to…
Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able…
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked…
CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers
A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in…
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model…
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
By Tarun Wig, Co-founder & CEO, Innefu Labs A bank in India can be doing everything right on paper. ISO certifications in place. RBI-mandated controls…
Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems
Levi Strauss & Co., the denim giant, reported a cybersecurity incident where an unauthorized third party accessed the company’s internal systems via a…
OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities
OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed…
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host
A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access…
Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID
A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to…
Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts
Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and…
CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges
A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its…
Google Chrome 151 Fixes 41 Security Flaws, Including 6 Critical Memory Bugs
Google has released Chrome 151 to the Stable channel, fixing 41 security vulnerabilities, including six critical memory-safety flaws that could enable…
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
An indirect prompt injection vulnerability in Claude on Chrome can be exploited to steal email verification codes and hijack accounts on platforms like…
