A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also…
Category: Cyber Security News
Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets
The Wireshark Foundation has released Wireshark 4.6.7, a security-focused update that fixes multiple vulnerabilities that can cause the popular network protocol analyzer to crash when processing specially crafted packets or capture files. Wireshark is widely used by security researchers, network…
Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks
A new security analysis by Binarly Research has uncovered six critical vulnerabilities in the widely used U-Boot bootloader, exposing embedded systems and server management platforms to denial-of-service (DoS) attacks and potential arbitrary code execution. U-Boot is a foundational component in…
OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks
OpenAI has released the GPT-5.6 model family for general availability, introducing three models aimed at different performance and cost requirements: Sol, the flagship system; Terra, a balanced option for routine professional workloads; and Luna, the fastest and lowest-cost member of…
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
A resurfaced Android banking trojan called RedHook has returned with a dangerous new trick, hijacking a legitimate developer feature to quietly seize deep control of infected phones. Rather than relying on complex exploits, the malware weaponizes ADB Wireless Debugging, a…
ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
A large hacking campaign is sweeping across websites worldwide, turning ordinary content management systems into launchpads for attackers. Small and medium sized businesses in Australia and beyond are finding their web servers quietly hijacked, often without obvious warning signs. The…
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
GodDamn ransomware has emerged as a serious threat, marking the third rebrand of a family that has quietly evolved since 2022. What makes this variant stand out is not just its encryption ability but the malicious kernel driver it uses…
HP Linux Printing Software Vulnerability Allows Remote Attackers to Execute Arbitrary Code
A critical security vulnerability has been identified in HP Linux Imaging and Printing (HPLIP) software that could allow remote attackers to execute arbitrary code on affected systems. The flaw, tracked as CVE-2026-14544, carries a high-severity CVSS v3 score of 9.8,…
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run…
RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Roundcube has released version 1.7 to patch six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that require zero user interaction to exploit. The update addresses issues discovered by researchers at Samsung R&D Institute Ukraine (SRUKR), among others,…
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
A large-scale AWS intrusion reveals how AI-assisted attackers can chain familiar cloud techniques to move from initial access to full environmental compromise in roughly 72 hours, not through novel exploits, but through unprecedented speed, scale, and orchestration. According to Sygnia’s…
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and patch security flaws before adversaries can exploit them a move that is already reshaping…
Windows Update Silently Installs LG Monitor App That Pushes McAfee Ads
A recent user report has raised concerns about Windows Update silently installing third-party applications, after an LG monitor-related app allegedly appeared on systems and began displaying McAfee advertisements without user consent. The issue surfaced in a discussion on Reddit’s r/pcmasterrace…
UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware
A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW. The campaign relies almost entirely on social engineering, which makes it dangerous because it feels routine to the people who…
20 Remote Code Execution Vulnerabilities Patched in Foxit PDF Reader and Editor
Foxit has patched 20 remote code execution vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, and users should update immediately. The fixes arrive in the July 8, 2026 security release and cover multiple Windows and macOS versions, with several…
AssuranceAmerica Data Breach Exposed 6.9 Million People’s License Numbers and Personal Data
AssuranceAmerica has disclosed a major data breach that exposed the personal information and driver’s license numbers of nearly 6.9 million individuals, marking one of the largest known leaks of U.S. driver’s license data in 2026. The incident highlights growing risks…
Operationalizing Threat Intelligence: Bridging the Gap Between Feed Data and SOC Action
Threat intelligence feeds have become a staple line item in security budgets. Yet a persistent gap exists between purchasing a feed and actually using it to stop attacks. Many SOC teams receive a steady stream of indicators — IP addresses,…
Everest Ransomware Claims 1 TB Data Theft But Encryptor Shows No Exfiltration Code
A new technical breakdown of the Everest ransomware family reveals a strange contradiction at the heart of one of its recent attack claims. Despite boasting about stealing a full terabyte of data from a victim organization, the actual malware sample…
GitHub Copilot Refuses Harmful Chat Prompts But Writes Them Inside Code Workflows
GitHub Copilot can refuse harmful prompts in chat while still generating the same harmful content inside code workflows when the request is decomposed across a multi-step IDE session. Researchers Abhishek Kumar and Carsten Maple from the Alan Turing Institute analyzed…
QR Codes Are the New Security Blindspots That Steal Your Card Details and Deliver Malware
A small pixelated square. You’ve scanned hundreds of them at coffee shops, parking meters, airport lounges, and restaurant tables. It feels instant. It feels safe. It feels routine. That’s exactly what cybercriminals are counting on. QR codes have become one…