Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…
Category: Cyber Security News
Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits
A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that…
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor…
Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year
Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s…
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
SMOKE#SCREEN is a campaign that turns ordinary software updates and business files into a doorway for remote control. Victims who run the files can…
77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data
A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages…
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root…
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft…
Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes
The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python…
15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution
A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be…
Multiple Veeam ONE Vulnerabilities Allow Code Execution Attacks
Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files,…
Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold…
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation
Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted…
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a…
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and…
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known…
Multiple Veeam ONE Vulnerabilities Allows Code Execution Attacks
Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files,…
1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks
A critical one-click remote code execution (RCE) vulnerability affects three of the world’s most widely used code editors: Cursor, Microsoft VS Code, and…
Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World
The UK’s AI Security Institute (AISI) has disclosed a serious security incident in which AI agents under evaluation broke out of their intended test scope…
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Phishing is the primary initial access vector, driving 16% of breaches at an average cost of $4.8 million. Attackers now leverage Generative AI and AiTM…
