A little-known Chinese company may have helped build the hidden network used to support military-linked cyber operations around the world. Researchers say…
Category: Cyber Security News
AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation
A serious Linux kernel zero-day vulnerability capable of local privilege escalation (LPE) has been uncovered by security researchers, underscoring both…
Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access
Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several older product releases and could lead to complete appliance compromise when exploited by…
PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing
PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration testers to delegate specific investigative tasks to AI agents while retaining full control…
Microsoft Teams Vishing Attack Uses Quick Assist to Deploy GoGRPC Backdoor
A new Microsoft Teams vishing campaign is using fake IT support calls to gain remote access to corporate systems. The attackers then deploy GoGRPC, a Go-based backdoor that can run commands, collect system details, and maintain access to compromised devices.…
Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File
Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be triggered when an application processes malicious files. Several issues can lead to heap…
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.…
How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory
Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync attack lets an adversary walk out with those hashes without…
CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks. The vulnerability affects Fortinet FortiOS, the operating system used across FortiGate firewalls and other Fortinet security products.…
Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders
Europol is enhancing its response to “The Com,” a dangerous online ecosystem that allegedly recruits and manipulates minors into cyberattacks, extortion schemes, sexual exploitation, and violent offenses. This initiative, called Project COMPASS, brings together law enforcement agencies from EU Member…
OpenAI CEO Sam Altman Claims AI Has Reached Singularity, Where Systems Improve by Themselves
OpenAI CEO Sam Altman has declared that artificial intelligence has entered the long-theorized singularity, a pivotal stage where AI systems begin improving themselves at an accelerating pace beyond traditional human control. Speaking on the “Relentless” podcast released Saturday, Altman framed…
Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot
A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled out a fix. The issue struck Linux platform builds 101.26042.0000 through 101.26042.0009, where…
Hackers Can Use MedusaHVNC to Control Your PC on a Desktop You Cannot See
A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim’s own computer, quietly loading their real browser profile, cookies, and logged-in sessions without any visible sign of intrusion. Sold as malware-as-a-service through…
Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw
The Vatican’s official Click to Pray app has exposed the personal information of more than 700,000 users through an unauthenticated API flaw. The issue allowed anyone with a web browser to retrieve account data without needing to sign in. Click…
GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates
GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a prevalent pattern in software supply chain attacks where attackers compromise a trusted package…
EY Data Breach Claimed by ShinyHunters Hacker Group
The notorious ShinyHunters extortion gang has publicly claimed responsibility for the Ernst & Young (EY) data breach, alleging it stole employee credentials and sensitive files through a supply-chain compromise of a third-party IT support platform. The claim, posted on the…
Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely
vBulletin has patched CVE-2026-61511, a critical remote code execution flaw that could let unauthenticated attackers execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The…
A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC
A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently hands attackers not one but two independent ways to remotely control infected computers. The infection starts with an email claiming…
NVIDIA Launches Open Secure AI Alliance to Build Open-Source Defenses for AI Agents
A coalition of over 30 technology industry leaders, including NVIDIA, Microsoft, CrowdStrike, Cisco, IBM, Palo Alto Networks, and Red Hat, has launched the Open Secure AI Alliance. The initiative aims to equip cyber defenders with transparent, community-driven AI security tools…
WalletService Privilege Escalation Flaw Allows Attackers Full Control of Windows Systems
Microsoft has addressed a local privilege escalation vulnerability in WalletService on Windows. This flaw could allow a standard user to gain full control over an affected machine, operating as \text{NT AUTHORITY\SYSTEM}. The vulnerability specifically affects WalletService, a LocalSystem component used…
