A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the…
Category: Cyber Security News
Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service
A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework,…
AI Double Agent Attack Turns Claude Desktop to Execute Remote Code on a Target Machine
A compromised email inbox can be weaponized into full remote code execution on a victim’s machine, not through malware or phishing links, but by turning the victim’s own Claude Desktop assistant against them. The attack uncovered by Security researchers at…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability
Proof-of-concept (PoC) exploit code and deep technical details have now been released for CVE-2025-53770, a critical remote code execution (RCE) vulnerability in on‑premises Microsoft SharePoint Server. This disclosure raises the risk of rapid weaponization and mass exploitation against unpatched SharePoint…
First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone
A full-chain exploit dubbed “IonStack” demonstrates how a single malicious URL click can hand attackers complete control over an Android device. The proof-of-concept by Nebula Security, described as the world’s first public Android 17 root demo, chains two zero-day vulnerabilities…
Hackers Exploit Roundcube N-Day Flaws to Steal Credentials and Deploy VShell
A newly identified hacking campaign is targeting university mail servers by exploiting known but unpatched flaws in Roundcube webmail software. The attackers are using these gaps to quietly steal login credentials and plant a powerful backdoor called VShell deep inside…
70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks
A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a growing security gap in the global web ecosystem, where millions…
CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in real-world attacks. The issue stems from…
15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions
A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed “GhostLock,” has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logic…
Discord’s Security Systems Mistakenly Banned 8,000+ Accounts Since May 2026
Discord has confirmed that a bug in its automated security systems led to the wrongful suspension of more than 8,000 user accounts between May 2026 and early July 2026. The company disclosed the issue via its official support account on…
China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks
UAT-7810, a China-nexus hacking group, is expanding a global network of hijacked internet devices by exploiting security flaws in Ruckus wireless routers and rolling out new custom malware. This activity feeds into what researchers call an Operational Relay Box network,…
OpenAI Reportedly Secures US Government Clearance to Launch GPT-5.6 Model
OpenAI has reportedly received approval from the U.S. Department of Commerce for a broad public launch of its advanced GPT-5.6 model, marking a significant moment in how Washington regulates access to frontier AI systems. A source familiar with the matter…
Accenture Data Breach – Hackers Allegedly Claim to Have Stolen 35 GB of Source Code
A threat actor operating under the alias “888” has posted a listing on a cybercrime forum claiming to sell data allegedly stolen from the IT services and consulting giant Accenture, with the stated haul totaling roughly 35 GB of source…
Anthropic Extends Free Access to Claude Fable 5 on All Paid Plans
Anthropic has extended promotional access to its newest AI model, Claude Fable 5, allowing subscribers on paid plans to use it at no additional cost through July 12, 2026, at 11:59:59 PM PT. The company confirmed the extension in an…
VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft
A ransomware strain called VECT has formed an unusual supply chain partnership with a threat group known as TeamPCP, quietly exposing thousands of organizations to compromise before any ransom note appears. VECT’s operators buy their way in using stolen credentials…
The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026. Emerging in mid-2025 from a payment dispute within the Qilin RaaS program, the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation that Microsoft tracks…
Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code
A critical vulnerability in Google Cloud Platform’s Dialogflow CX that lets attackers inject persistent malicious code into an organization’s AI-powered chatbot pipeline. The flaw, dubbed “Rogue Agent,” disclosed by Varonis Threat Labs, could silently exfiltrate conversations and enable large-scale phishing…
Ubiquiti Disclosed 25 Security Vulnerabilities Across the UniFi Ecosystem
Ubiquiti has disclosed 25 security vulnerabilities affecting its UniFi ecosystem in Security Advisory Bulletin 066, including several critical flaws rated 9.9 and 10.0 on the CVSS v3.1 scale that could allow network-based attackers to fully compromise devices. The advisory spans…
AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection
A new phishing campaign is turning a trusted remote access tool into a long term backdoor for espionage. Attackers hide behind fake invoices to slip past email filters, and once inside a network they rely on everyday IT software rather…
GitLost Vulnerability Tricks GitHub’s AI Agent into Leaking Private Repos
A newly disclosed vulnerability dubbed “GitLost” shows how attackers can weaponize a single GitHub Issue to trick GitHub’s new AI-powered Agentic Workflows into leaking private repository contents to the public internet, with no credentials, coding skills, or system access required.…
