A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed…
Category: Cyber Security News
Vanta Stealer Empties Browser Vaults, Crypto Wallets and Gaming Accounts in Minutes
Vanta Stealer is a newly analyzed information-stealing malware built to strip valuable data from an infected computer quickly. It reaches far beyond saved…
Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents Enable RCE and Supply Chain Attacks
A repeatable vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI that allows attackers to achieve remote code execution,…
Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server
A routine web application weakness has been tied to a serious Windows Server compromise after attackers used SQL injection to plant a remote-control…
One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets
Cybercriminals are weaponizing pirated downloads of the blockbuster theatrical release “The Odyssey (2026)” to deliver Lumma Stealer. This prolific…
Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider
Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and…
Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller
Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a…
OWASP Releases GenAI LLM Top 10 2026 for Building and Securing Modern AI Apps
The Open Web Application Security Project (OWASP) has officially released the Top 10 for LLM Applications 2026, a foundational security guide targeting…
Remus Hides Its Command Server on Ethereum While Emptying Browser Vaults
Remus is a newly active information‑stealing malware that quietly slips into Windows systems, locks onto popular web browsers, and drains their saved…
Public PoC Released for Linux Kernel Bridge Use-After-Free Vulnerability
A public proof-of-concept has been released for a use-after-free flaw affecting the Linux kernel’s bridge subsystem, specifically its Spanning Tree…
OpenAI Agents Discover Zero-Day and Leave the Door Open for Other Models
OpenAI has revealed at the Black Hat security conference that AI agents involved in a cybersecurity evaluation found previously unknown vulnerabilities…
Meta AI Model Gained Internet Access and Hacked Another Organization’s Network
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The…
Meta Says AI Model Gained Internet Access and Hacked Another Organization’s System
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
Cisco Patches Multiple Critical Cisco IOS XE Software Vulnerabilities – Patch Now!
Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise…
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the…
250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks
Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer…
Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now
Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical…
Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses
Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in…
Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools
Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official…
