A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, encrypt, and potentially upload users’ browsing-domain data. The extension reportedly had about 1.6…
Category: Cyber Security News
Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide
Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…
New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials
CrashStealer, a native C++ macOS infostealer that disguises itself as Apple’s built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before encrypting and exfiltrating everything to a remote command-and-control server. Jamf first spotted a…
NSA Urges Organizations to Disable Cisco Smart Install as Russian Hackers Target Routers
The National Security Agency, alongside 17 international partner agencies, released a joint Cybersecurity Advisory on July 9, 2026, warning that Russian state-sponsored actors continue to exploit vulnerable and poorly configured network infrastructure across critical sectors. The advisory, titled “Improve Router…
AI-Powered ‘Intelligent Worm’ Could Regenerate Exploits and Adapt to Defenses in Real Time
A new threat model is raising hard questions about how quickly self-spreading malware could change during an attack. The proposed Intelligent Worm is not a confirmed strain found in the wild, but a scenario in which a worm uses an…
CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has added two high-risk Joomla extension flaws to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities allow unrestricted file uploads, a weakness that attackers can abuse to upload malicious files and potentially take…
Hackers Using Vibe-Coded Generated PowerShell Script to Enumerate Active Directory Accounts
Threat actors have started weaponizing AI-generated PowerShell code to map Active Directory (AD) environments, marking a notable shift from off-the-shelf hacking tools to bespoke, “vibe-coded” malware. Security researchers at Huntress recovered and reconstructed one such script, dubbed Untitled1.ps1, from an…
Debian 13 Released With Security Updates, Bug Fixes and Driver Updates
The Debian Project has released Debian 13.6, the latest maintenance update for Debian 13 “trixie.” The point release focuses on security corrections and fixes for serious software issues across the operating system’s package collection. Debian 13.6 is not a new…
iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation
A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…
Armored Likho APT Uses AI-Generated Loaders to Deploy BusySnake Stealer Against Government Targets
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer. The operation has targeted government agencies and electrical power organizations, putting sensitive public-sector data and essential services at risk. Confirmed victims span…
VEXAIoT Multi-Agent System Automates IoT Reconnaissance and Exploit Execution
Security researchers have introduced VEXAIoT, an AI-powered multi-agent framework designed to automate vulnerability discovery and exploit execution against Internet of Things environments. The research shows how large language model agents can coordinate reconnaissance, attack planning, command generation, and result validation…
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carries…
SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection
SpyGlace has returned in a campaign that hides malicious activity behind online services many companies trust. The operation, linked to APT-C-60, uses spear-phishing emails to steer victims toward a booby-trapped archive and then installs malware through a chain of ordinary…
Anthropic Extends Claude Fable 5 Access From July 12 to July 19
Anthropic has extended promotional access to Claude Fable 5 until July 19, 2026, giving eligible paid subscribers more time to use the company’s newest AI model at no additional charge. The offer was previously scheduled to end earlier. However, Anthropic…
Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers
A supply chain attack on the jscrambler npm package, a JavaScript code-protection tool with over 15,800 weekly downloads, involved malicious versions that silently deployed native malware on Linux, macOS, and Windows systems. Socket Research Team detected the first malicious release,…
One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers
A forgotten web server can become a window into a criminal operation. In this case, a Python HTTP service left exposed on a virtual private server revealed the working materials of several attackers. The discovery offers a rare look at…
Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT
A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package that appears connected to a real seminar. The attackers used information from an…
Hackers Can Exploit Motorola MR2600 Firmware Update Process to Gain Code Execution
A newly disclosed unauthenticated remote code execution vulnerability in Motorola MR2600 Wi-Fi routers allows attackers on the local network to upload and install a malicious firmware image without logging in to the router’s administration panel. According to researcher MrBruh, the…
Citrix Unveils NetScaler MCP Gateway With Centralized Security for AI Agents
Citrix has introduced new NetScaler capabilities designed to secure and govern enterprise AI agents that use the Model Context Protocol (MCP). Announced on July, the NetScaler MCP Gateway provides a centralized entry point for AI agents connecting to approved MCP…
Microsoft Testing Copilot Feature That Shows What’s Slowing Down Your Windows 11 PC
Microsoft is quietly testing a new Copilot capability called “PC Insights” that lets the AI assistant analyze your Windows 11 machine’s hardware and pinpoint exactly what’s causing slowdowns. The feature is currently rolling out slowly in the United States and…
