A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit…
Category: Cyber Security News
MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to…
Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Software developers are being targeted with fake job offers that turn routine coding tests into a path for remote access malware. The campaign uses…
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns…
Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls
Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company…
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories
Cybercriminals are widening the reach of information-stealing malware by targeting the local data created by AI coding agents. The shift puts access…
Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code
Microsoft has released security updates for CVE-2026-69485, an Important-rated remote code execution vulnerability affecting the Windows Remote Desktop…
Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Hackers are using Google Sheets as an unlikely control channel in a cryptocurrency theft campaign. The operation turns a familiar browser session into a…
Top 10 Best Mobile Threat Defense (MTD) Solutions in 2026
Bottom line up front: if you already run Microsoft 365 E5, Defender for Endpoint’s mobile capability covers the common cases at no extra cost start there…
Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
A large cryptomining operation has compromised 3,562 Redis servers and turned their processing power into a source of Monero revenue. The campaign did not…
Top 10 Best Patch Management Software in 2026
Patching remains the single highest-value security control most organizations execute badly. Automox leads on cloud-native simplicity, Tanium on speed at…
Top 10 Best Mobile Device Management (MDM) Solutions in 2026
Bottom line up front: Microsoft Intune wins by default for Microsoft 365 organizations because you already own it. Jamf wins outright for Apple estates.…
Top 10 Best Unified Endpoint Management (UEM) Solutions in 2026
Bottom line up front: if you’re a Microsoft 365 organization, Intune is almost certainly your answer and the only real question is what it doesn’t cover.…
New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server
cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of…
New Windows Defender ShieldCrash 0-Day Bypasses Microsoft Patch to Read Files as SYSTEM
A newly published ShieldCrash proof of concept from researcher MSNightmare claims that Microsoft Defender remains vulnerable to an arbitrary file-read…
Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely
Microsoft has disclosed a new security flaw in Windows BitLocker, the operating system’s built-in disk encryption feature, that could let an attacker…
Top 10 Best Application Control & Allowlisting Tools in 2026
Allowlisting inverts the security model: instead of detecting bad software, only approved software runs. Done well, it stops ransomware protection threats…
CISA Warns Chinese AI Firms Extract Billions of Tokens From Claude, GPT, Gemini and Grok
A new U.S. government advisory has raised concerns over large-scale attempts to copy the capabilities of leading artificial intelligence systems. The…
Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild
Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on…
FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests
Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit…