The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component…
Category: Cyber Security News
Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks
Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing Language) searches. Three…
Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access
Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account…
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks
A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell
A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, immediately open a…
F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks
F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, warning that unauthenticated attackers could exploit them to trigger memory corruption, crash worker processes, or, in the worst case, execute arbitrary code. The vulnerabilities, published on July…
Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend?
Destiny Stealer activity is rising across Europe and the US, putting corporate accounts, remote access, email data, and sensitive business information at risk. A single infected endpoint can expose passwords, session cookies, VPN details, Outlook data, cryptocurrency wallets, Wi-Fi profiles,…
Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS
Threat actors are hijacking Anthropic’s Claude AI platform and Google Ads to trick Mac users into infecting themselves with a dangerous new information-stealing malware called MacSync Stealer, according to Zscaler Threat Hunting. The infection begins when a victim searches for…
GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches
OpenAI’s GPT-5.6 Sol Ultra model independently constructed a complete, working exploit chain for Google Chrome, using nothing but publicly available security patch commits as its starting point. Researchers from Hacktron tasked three frontier AI models, GPT-5.6 Sol Medium, Sol Ultra,…
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
A critical unpatched vulnerability in Cursor, the popular AI-powered code editor used by over 7 million developers, allows attackers to achieve arbitrary code execution on Windows systems. Simply opening a malicious repository is sufficient to trigger this execution path, requiring…
Microsoft Confirms Dell Laptops Shut Down, Increase Heat Following July Windows Update
Microsoft has confirmed that a limited number of Dell laptops may suffer unexpected shutdowns, higher temperatures, battery drain, and poor performance after installing a recent Windows 11 preview update. The issue was first reported by Dell during internal testing and…
CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-56164, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. This flaw affects on-premises deployments of Microsoft SharePoint Server and…
Hackers Abuse FaceTime Calls to Impersonate Banks and Hijack Victims’ Accounts
Apple has issued a security advisory warning iPhone and iPad users to treat unexpected FaceTime calls with the same scrutiny as standard phishing emails. A newly tracked wave of social engineering scams shows threat actors actively impersonating major financial institutions…
Multiple Windows RDP Vulnerabilities Allow Attackers to Access Sensitive Data
Microsoft has released security updates to address a series of information disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). These vulnerabilities could allow attackers to read sensitive data from system memory during remote sessions. They affect a wide range…
Multiple Dell PowerProtect Vulnerabilities Allow Hackers to Gain Full System Access Remotely
Dell has released security updates to address multiple critical vulnerabilities in its PowerProtect Data Domain products that could allow an unauthenticated remote attacker to gain complete control of affected systems. The vulnerabilities impact several PowerProtect Data Domain platforms, including Data…
Chrome 150 Security Update Patches 15 Flaws, Including Two Critical Code Execution Ones
Google has rolled out Chrome version 150.0.7871.124/.125 for Windows and macOS, and version 150.0.7871.124 for Linux users. This Stable Channel update addresses 15 security vulnerabilities, including two critical memory safety issues in Ozone. The update will be released gradually and…
Critical SonicWall Firewall 0-Day Vulnerabilities Actively Exploited in Attacks
SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA1000 Series appliances. The company is warning that attackers are actively exploiting these flaws in real-world attacks. The most critical issue, tracked as CVE-2026-15409, carries a maximum CVSS…
New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry
A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files…
Gamers Download Fake Cheats and Hand Attackers a Live Remote Control of Their Windows PCs
New research uncovered 11 malicious NuGet packages disguised as game cheats, bots, and management panels for popular online titles. The campaign targets gaming communities playing titles such as Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and Liberty. Once installed,…
Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Government Cyberattacks
An active, highly structured intrusion campaign co-opting commercial artificial intelligence platforms as operational engines for state-sponsored operations. Rather than acting as peripheral research tools, Claude Code and DeepSeek-v4-pro were embedded directly into the core execution flows of a China-linked cyber…