Odyssey Stealer is again targeting macOS users, with a recent surge affecting victims in more than 100 countries. The information-stealing malware is built to collect credentials, browsing data, cryptocurrency assets, and other sensitive files that can quickly expose both personal…
Category: Cyber Security News
Django SQL Injection Vulnerability Actively Exploited in the Wild
A high-severity SQL injection vulnerability in the Django web framework is now being actively exploited in real-world attacks, raising concerns for organizations running geospatial applications on PostGIS-backed deployments. The flaw, tracked as CVE-2026-1207, affects Django’s GIS module and has been…
GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices
GigaWiper is a newly identified Windows threat built to do more than steal information or lock a screen. Once activated, it can erase disks, scramble files beyond recovery, and leave organizations facing sudden outages. Its arrival shows how destructive malware…
Ransomware Negotiator Sentenced for BlackCat Ransomware Operators to Attack Victims
A former Florida ransomware negotiator has been sentenced to 70 months in federal prison after conspiring with BlackCat/ALPHV ransomware operators and helping attack multiple U.S. victims. Angelo Martino, of Land O’Lakes, Florida, worked for a U.S.-based cyber incident response company.…
Hackers Turn 50+ Dormant GitHub Accounts Into a Network for Corporate Source Code Recon
Research has uncovered coordinated campaigns that use more than dormant GitHub accounts to map corporate organizations, repositories, and developers. The activity relies on GitHub’s API to collect public information. However, some operators have also attempted to access private source code…
Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft
A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also…
Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets
The Wireshark Foundation has released Wireshark 4.6.7, a security-focused update that fixes multiple vulnerabilities that can cause the popular network protocol analyzer to crash when processing specially crafted packets or capture files. Wireshark is widely used by security researchers, network…
Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks
A new security analysis by Binarly Research has uncovered six critical vulnerabilities in the widely used U-Boot bootloader, exposing embedded systems and server management platforms to denial-of-service (DoS) attacks and potential arbitrary code execution. U-Boot is a foundational component in…
OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks
OpenAI has released the GPT-5.6 model family for general availability, introducing three models aimed at different performance and cost requirements: Sol, the flagship system; Terra, a balanced option for routine professional workloads; and Luna, the fastest and lowest-cost member of…
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
A resurfaced Android banking trojan called RedHook has returned with a dangerous new trick, hijacking a legitimate developer feature to quietly seize deep control of infected phones. Rather than relying on complex exploits, the malware weaponizes ADB Wireless Debugging, a…
ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
A large hacking campaign is sweeping across websites worldwide, turning ordinary content management systems into launchpads for attackers. Small and medium sized businesses in Australia and beyond are finding their web servers quietly hijacked, often without obvious warning signs. The…
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
GodDamn ransomware has emerged as a serious threat, marking the third rebrand of a family that has quietly evolved since 2022. What makes this variant stand out is not just its encryption ability but the malicious kernel driver it uses…
HP Linux Printing Software Vulnerability Allows Remote Attackers to Execute Arbitrary Code
A critical security vulnerability has been identified in HP Linux Imaging and Printing (HPLIP) software that could allow remote attackers to execute arbitrary code on affected systems. The flaw, tracked as CVE-2026-14544, carries a high-severity CVSS v3 score of 9.8,…
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run…
RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Roundcube has released version 1.7 to patch six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that require zero user interaction to exploit. The update addresses issues discovered by researchers at Samsung R&D Institute Ukraine (SRUKR), among others,…
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
A large-scale AWS intrusion reveals how AI-assisted attackers can chain familiar cloud techniques to move from initial access to full environmental compromise in roughly 72 hours, not through novel exploits, but through unprecedented speed, scale, and orchestration. According to Sygnia’s…
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and patch security flaws before adversaries can exploit them a move that is already reshaping…
Windows Update Silently Installs LG Monitor App That Pushes McAfee Ads
A recent user report has raised concerns about Windows Update silently installing third-party applications, after an LG monitor-related app allegedly appeared on systems and began displaying McAfee advertisements without user consent. The issue surfaced in a discussion on Reddit’s r/pcmasterrace…
UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware
A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW. The campaign relies almost entirely on social engineering, which makes it dangerous because it feels routine to the people who…
20 Remote Code Execution Vulnerabilities Patched in Foxit PDF Reader and Editor
Foxit has patched 20 remote code execution vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, and users should update immediately. The fixes arrive in the July 8, 2026 security release and cover multiple Windows and macOS versions, with several…
