WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its…
Category: Cyber Security News
A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online
A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create…
Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
Broadcom has released a critical security advisory, VMSA-2026-0006, addressing multiple high-impact vulnerabilities across core VMware virtualization…
VulnGym Uses AI-Trained APT Attackers to Stress-Test Enterprise Patching Strategies
A new cybersecurity research tool called VulnGym utilizes reinforcement learning to simulate AI-trained advanced persistent threat (APT) attackers…
CISA Releases Checklist for Critical Infrastructure Organizations to Isolate Vital Systems
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center…
AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers…
Bank of Baroda Data Breach – Hackers Gained Access Via Employee Email Account
Bank of Baroda has confirmed a cybersecurity incident in which attackers gained unauthorized access to an employee’s email account, exposing internal…
Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely
A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This…
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2
A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete…
Hackers Are Hiding Commands in Emails to Trick the AI Systems Protecting You
Attackers are beginning to hide malicious instructions inside ordinary emails, documents, calendar invites, and online advertisements. The goal is not…
Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers
A cluster of malicious npm packages has been used to deliver a cross-platform remote access trojan against developers who use Alibaba-related tools. The…
First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face
Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day…
OpenAI Open-Sources Codex Security CLI for Finding, Validating, and Fixing Security Vulnerabilities
OpenAI has open-sourced Codex Security, a command-line tool and TypeScript SDK designed to help developers find, validate, and fix security…
Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years
Anthropic researchers using Claude Mythos Preview have uncovered mathematical flaws in major cryptographic algorithms that human experts failed to spot…
JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution
JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass…
Chrome Extension Monitors AI Conversations Across ChatGPT, Claude, Gemini, and Other Platforms
A Chrome extension with roughly 100,000 installs is quietly harvesting every prompt and AI response typed across nine major artificial intelligence…
Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code – PoC Released
A high-severity heap buffer overflow in NGINX Plus and NGINX Open Source can let unauthenticated attackers crash worker processes and, under certain…
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth…
Apple iOS 26.6 Fixes Flaws Enabling Kernel Code Execution, Root Access and Sandbox Escape
Apple has released iOS 26.6 and iPadOS 26.6 to address a significant number of security vulnerabilities, including flaws that could allow malicious…
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
A Formula 1 pit crew doesn’t wait until every sensor, camera, and engineer agrees that a tire needs changing. They have a few seconds to make a decision…
