The Debian Project has released Debian 13.6, the latest maintenance update for Debian 13 “trixie.” The point release focuses on security corrections and fixes for serious software issues across the operating system’s package collection. Debian 13.6 is not a new…
Category: Cyber Security News
iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation
A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…
Armored Likho APT Uses AI-Generated Loaders to Deploy BusySnake Stealer Against Government Targets
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer. The operation has targeted government agencies and electrical power organizations, putting sensitive public-sector data and essential services at risk. Confirmed victims span…
VEXAIoT Multi-Agent System Automates IoT Reconnaissance and Exploit Execution
Security researchers have introduced VEXAIoT, an AI-powered multi-agent framework designed to automate vulnerability discovery and exploit execution against Internet of Things environments. The research shows how large language model agents can coordinate reconnaissance, attack planning, command generation, and result validation…
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carries…
SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection
SpyGlace has returned in a campaign that hides malicious activity behind online services many companies trust. The operation, linked to APT-C-60, uses spear-phishing emails to steer victims toward a booby-trapped archive and then installs malware through a chain of ordinary…
Anthropic Extends Claude Fable 5 Access From July 12 to July 19
Anthropic has extended promotional access to Claude Fable 5 until July 19, 2026, giving eligible paid subscribers more time to use the company’s newest AI model at no additional charge. The offer was previously scheduled to end earlier. However, Anthropic…
Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers
A supply chain attack on the jscrambler npm package, a JavaScript code-protection tool with over 15,800 weekly downloads, involved malicious versions that silently deployed native malware on Linux, macOS, and Windows systems. Socket Research Team detected the first malicious release,…
One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers
A forgotten web server can become a window into a criminal operation. In this case, a Python HTTP service left exposed on a virtual private server revealed the working materials of several attackers. The discovery offers a rare look at…
Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT
A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package that appears connected to a real seminar. The attackers used information from an…
Hackers Can Exploit Motorola MR2600 Firmware Update Process to Gain Code Execution
A newly disclosed unauthenticated remote code execution vulnerability in Motorola MR2600 Wi-Fi routers allows attackers on the local network to upload and install a malicious firmware image without logging in to the router’s administration panel. According to researcher MrBruh, the…
Citrix Unveils NetScaler MCP Gateway With Centralized Security for AI Agents
Citrix has introduced new NetScaler capabilities designed to secure and govern enterprise AI agents that use the Model Context Protocol (MCP). Announced on July, the NetScaler MCP Gateway provides a centralized entry point for AI agents connecting to approved MCP…
Microsoft Testing Copilot Feature That Shows What’s Slowing Down Your Windows 11 PC
Microsoft is quietly testing a new Copilot capability called “PC Insights” that lets the AI assistant analyze your Windows 11 machine’s hardware and pinpoint exactly what’s causing slowdowns. The feature is currently rolling out slowly in the United States and…
SpaceX and Starlink X Account Reportedly Compromised to Push Fake Crypto Coins
The official SpaceX and Starlink accounts on X appear to have briefly promoted a fraudulent cryptocurrency after being compromised, with the scam token subsequently “rug-pulled” on unsuspecting buyers. Multiple online reports indicate that an account calling itself “Sam Catman,” displaying…
KittySploit – AI-Powered Next-Generation Penetration Testing Framework With 1150+ Modules
KittySploit is a new open-source penetration testing framework that combines a Python and Zig codebase with autonomous AI agents, shipping with over 1,150 modules for offensive security teams. The tool chain includes reconnaissance, exploitation, traffic analysis, payload generation, collaboration, and…
Cyber Security Newsletter and Bulletin Weekly – 16-Year-Old Linux, Ubiquiti Flaws, Accenture Breach, Android 17 Exploit +20 Stories
This week’s bulletin exposes just how long dangerous flaws can hide in plain sight, with a 16-year-old Linux KVM escape bug and a 15-year-old kernel privilege escalation flaw both surfacing after more than a decade undetected. Enterprise infrastructure took a…
Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets
Apple has filed a federal lawsuit against OpenAI, accusing the ChatGPT maker of orchestrating a systematic campaign to steal confidential hardware designs, manufacturing processes, and supplier relationships through more than 400 former Apple employees now working at OpenAI. The 41-page…
New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents
A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such as .env files. The ASSET Research Group demonstrated that a pull request containing…
Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens
Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older than macOS Tahoe 26.4, and Microsoft has…
Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts
Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per…