Iranian-affiliated hackers are targeting internet-connected industrial controllers used across critical infrastructure in the United States. Their activity can disrupt essential processes in water, energy, and government environments, where even a small change to control logic can create serious real-world consequences.…
Category: Cyber Security News
Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets
Cryptocurrency theft is increasingly moving beyond the screen. Criminals are using violence, threats, home invasions, and kidnapping attempts to force victims to unlock wallets or approve transfers while under pressure. These incidents are known as wrench attacks, a term that…
Claude Opus 5 Finds Vulnerabilities but Remains Restricted in Generating Exploits
Anthropic has officially released Claude Opus 5, a next-generation large language model (LLM) designed to boost software engineering and complex knowledge-work performance while keeping tight reins on offensive cybersecurity capabilities. Positioned as the default model on Claude Max and the…
Researchers Find 84 Hidden iOS Data Streams Tracking Apps, Locations and Messages
Apple’s Biome framework is drawing fresh attention after researchers identified 84 data streams that can preserve detailed records of how an iPhone is used. The findings do not describe malware or an active intrusion. Instead, they show how built-in iOS…
Microsoft Moves Enterprise Windows Activation From Software to Hardware Verification
Microsoft is preparing to transition its enterprise Windows activation from a software-trust model to one based on verified hardware. The company announced KMS Hardware-Secured. A new Key Management Service capability that uses Trusted Platform Module (TPM) attestation to validate KMS…
Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks
Weekly threat telemetry from ANY.RUN’s interactive sandbox shows Vidar stealer, AsyncRAT, and XWorm remained the three most-uploaded malware samples analyzed by security teams during the week of July 20-26, 2026, collectively accounting for hundreds of sandbox detonations as defenders raced…
Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files
Claude Code can load files from outside a repository through a symlinked memory import, which may allow local data to be included in the model’s first outbound request before the model performs any actions. A recently reported Claude Code issue…
Anthropic’s Claude Opus 5 Arrives on AWS With Improved Cybersecurity Capabilities
AWS has introduced Anthropic’s Claude Opus 5 on Amazon Bedrock and the Claude Platform on AWS, bringing a new high-capability AI model to enterprise cloud environments. Anthropic claims that Claude Opus 5 enhances capabilities in coding, document analysis, visual understanding,…
Hackers are Setting Up Websites Impersonating Popular Windows Apps to Deliver Malware
Hackers are quietly building lookalike websites that pretend to be popular Windows apps, then use those pages to push malware onto unsuspecting users. The scheme already covers more than 70 well known utilities that people trust and download every day.…
Windows 11’s File Explorer Is Now Faster at Deleting Large Files
Microsoft is rolling out a targeted performance update for Windows 11 designed to resolve one of the platform’s most persistent storage annoyances: sluggish deletion of large, highly fragmented files. The improvement is part of a broader set of File Explorer…
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of…
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts. Those stolen identities…
SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos
A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones. Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and…
Google Is Giving Hacker Groups New Names That Reveal Who They Are and Why They Attack
Google is changing how it names the hacker groups it tracks, replacing a patchwork of labels with names designed to explain more at a glance. The change is intended to make threat reports easier to follow when defenders are trying…
PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new security measure that prevents users from uploading new files to package releases that are more than 14 days old. This change aims to stop attackers from adding malicious files to trusted Python package versions after…
Researchers Successfully Booted Jailbroken Version of iOS 27 on an iPhone 11 Pro
Security researchers have successfully booted a jailbroken build of iOS 27 on an iPhone 11 Pro by combining the recently disclosed usbliter8 SecureROM exploit with a heavily modified custom firmware workflow. The demonstration targets Apple’s A13-powered iPhone 11 Pro. It…
Eight NodeBB Vulnerabilities Let Hackers Read Your Private Chats and Take Over the Forum
Eight high-severity vulnerabilities have been discovered in NodeBB, a popular Node.js-based forum platform, exposing millions of users to risks including private message leaks, stored cross-site scripting (XSS), and full forum compromise. The issues affect all NodeBB versions prior to 4.14.0…
Claude AI Shared Chats Reportedly Exposed in Google Search Results
Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations. A Reddit post this weekend revealed that hundreds of Claude AI shared chats were publicly discoverable through Google. Users searching queries…
Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories
Threat actors continued to combine classic exploitation techniques with AI-accelerated tooling this week, from a 15-year-old NGINX bug and an actively exploited Check Point authentication flaw to autonomous AI agents chaining zero-days against Hugging Face. Below is a roundup of…
How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict
The current conflict between the United States and Iran has become a case study in how asymmetric warfare and coalition building are reshaping the cyber and geopolitical dimensions of modern conflict. Following the United States and Israel’s joint military strikes…
