A vulnerability chain in Anthropic’s Claude Cowork allows an attacker with local code execution to escalate privileges and run arbitrary commands as root inside the product’s isolated Linux sandbox, bypassing every layer of defense Anthropic built into the environment. Claude…
Category: Cyber Security News
Ousaban Malware Uses Phishing PDFs and VBS Downloader to Target Iberian Banking Users
A newly documented campaign is quietly hijacking online banking sessions across Spain and Portugal, and it starts with something as ordinary as a broken PDF file. The malware behind it, known as Ousaban, has resurfaced with a fresh set of…
AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery
AsyncRAT is back in the headlines, and the attackers behind it have found a clever way to hide in plain sight. Instead of relying on suspicious servers, they use Dropbox links and TryCloudflare tunnels, both trusted services that most security…
Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access
A newly uncovered phishing panel called ARToken is giving cybercriminals an easy way to steal Microsoft 365 login sessions without ever touching a password. The tool works by abusing a legitimate Microsoft sign in feature meant for devices without a…
AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access
A stealthy campaign is turning trusted remote access software into a weapon against everyday users and businesses. Attackers have hidden the AsyncRAT trojan inside fake software installers, letting it slip past basic security checks. The campaign relies on DLL sideloading…
CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a coordinated scanning-and-exploitation campaign across three separate sensor deployments. Within 24 hours of Citrix…
ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files
A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd through the platform’s file download mechanism. According to Security researcher zer0dac, OpenAI has…
DHS Confirms Breach of Information-Sharing Network Platform HSIN
The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform relied upon by federal, state, local, tribal, territorial, international, and private-sector partners to coordinate emergency response and share threat…
Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys
Ransomware has always needed a human at the keyboard or writing the script behind it. That assumption no longer holds. Researchers have documented what appears to be the first fully autonomous ransomware operation, driven entirely by an AI agent rather…
Microsoft Outlook Bug Removes Copilot Button For Windows Users
A software defect in classic Outlook for Windows caused Copilot Chat and Copilot entry points to vanish for affected users, with Microsoft confirming the issue was tied to specific Basic-tier Copilot licenses. The bug has since been resolved through a…
Opera Blocks Clipboard Attacks, Including ClickFix, With New Paste Protect Feature
Opera has introduced a new built-in security feature called Paste Protect, designed to defend users against clipboard-based cyberattacks, including the increasingly common ClickFix technique. The feature is now integrated directly into the Opera browser. It is enabled by default, providing…
Hackers Use Fake VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers have uncovered a campaign that abuses the popular VLC media player to quietly install ValleyRAT,…
900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation
More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerability in the platform, putting mission‑critical ERP environments at immediate risk of compromise. Recent scanning data…
Hackers Disable Defender, Sysmon, and WAF Before Dumping Credentials With Mimikatz
Hackers have found a new way to blind security teams before stealing passwords, and the technique is as thorough as it is alarming. A threat actor recently disabled Microsoft Defender, killed the Sysmon logging tool, and tore down a web…
FCC Announces Bans on Chinese Equipment Linked to Cybersecurity Risks
The U.S. Federal Communications Commission (FCC) has announced a sweeping ban on the import and sale of certain Chinese-made telecommunications equipment linked to cybersecurity risks and potential espionage. The decision, issued on June 26, 2026, targets devices from companies listed…
Critical JetBrains Vulnerabilities Enable Authentication Bypass and Code Execution Attacks
JetBrains has released security updates for a cluster of critical vulnerabilities that enable authentication bypass, account takeover, and remote code execution (RCE) across its on‑premise ecosystem, including Hub, YouTrack, IntelliJ‑based IDEs, Kotlin, GoLand, and TeamCity. These flaws put development and…
WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes
WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or…
Medtronic Confirms Data Breach – Hackers Gained Access to Corporate IT Systems
Medical technology giant Medtronic Inc. has disclosed a cybersecurity incident involving unauthorized access to its corporate IT systems, potentially affecting sensitive personal and health-related information of patients using Medtronic medical devices. Medtronic detected unusual activity in certain corporate IT systems…
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition
Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. The flaws affect Windows, Linux, and macOS, with the highest impact on Windows,…
Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos
A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing a legitimate Chrome feature meant for photo editing. The attack begins with something…
