Zimbra has released a security update to address a critical vulnerability in the Zimbra Classic Web Client that could allow malicious actors to compromise user accounts and execute unauthorized code. The company recommends that customers install the latest update…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Authentic GitHub Repository Can Trick AI Agents Into Installing Malware
An agentic AI coding tool built for making a GitHub repository and cloning could launch a malicious payload that stays hidden to AI agents, human reviewers, and security scanners. Malicious payload with no exploit code Experts from Mozilla Zero Day…
Operation Endgame Disrupts Global Cyber Crime Assembly Line
Private companies and international authorities have disrupted a malicious “assembly line” that let hackers steal millions of login details and theft of $47 million in ransom payments via extortion. The operation aimed at catching two tools that are used in…
Centre Plans New Cybersecurity Norms for Electric Two- and Three-Wheelers to Address Battery Tampering Risks
The Central government is preparing to introduce new cybersecurity measures aimed at preventing unauthorised tampering with the batteries of electric two-wheelers and three-wheelers. The proposed regulations are expected to mandate stronger software security standards for electric scooters and e-rickshaws,…
India Orders Telegram to Crack Down on Pirated Movies and OTT Content, Seeks Compliance Report
Ministry of Information and Broadcasting (MIB) has directed the messaging platform Telegram to take down the pirated films, OTT content and other audio-visual material uploaded on it. It also called upon the company to put in place measures to…
Google Sent Earthquake Warnings Before Venezuela Tremor Reached Millions
In Venezuela, millions of Android users received earthquake alerts on their phones just minutes before two devastating 7.1 and 7.5 earthquakes struck, highlighting the increasing importance of smartphone-based early warning systems for disaster response. Google reported that its Android Earthquake…
JadePuffer: First AI-Agent Ransomware Automates Entire Attack
Security researchers have identified JadePuffer as the first ransomware operation conducted entirely by an AI agent, marking a watershed moment in automated cyberattacks. Discovered by cloud security firm Sysdig, this incident demonstrates how large language model (LLM) agents can…
Meta Faces Privacy Questions After Employee Data Exposure Report
After sensitive employee information was reportedly made available throughout the organization, Meta has suspended an internal employee monitoring initiative intended to assist in the development of artificial intelligence systems. Initially introduced in April, the Model Capability Initiative was intended…
Six U-Boot Vulnerabilities Could Enable Pre-Boot Code Execution and Persistent Firmware Attacks
Security researchers have identified six vulnerabilities in the widely deployed U-Boot bootloader that could allow attackers to execute malicious code during the earliest stages of a device’s startup process. If successfully exploited, the flaws could enable firmware-level attacks capable…
U.S. Security Expert Sentenced for Aiding BlackCat Ransomware Gang
A cybersecurity professional has become the third U.S. security expert sentenced to prison for aiding a ransomware gang, marking a significant escalation in insider threat cases involving incident response firms. Angelo Martino, a 41-year-old from Florida, pleaded guilty to…
Injective Labs GitHub Compromise Distributes Malicious npm Package Targeting Crypto Wallet Keys
Cybersecurity researchers have detected a software supply chain attack in which threat actors compromised the Injective Labs SDK GitHub repository and utilized it to distribute a backdoored version of the npm package containing cryptocurrency wallet credentials stealing capabilities. Researchers…
Hackers Target Industries in Japan, Attacks Share One Pattern
Four big Japan cyberattacks point to a common trend: threat actors are getting access via third-party infrastructure and subsidiaries, not from corporate headquarters. While the attacks impacted companies from varying industries such as telecommunications, manufacturing, insurance, and brewing, the breaches…
Injective SDK Supply Chain Attack Exposed Developers to Cryptocurrency Wallet Theft
InjectiveLabs/SDK-TS, a widely used package, was briefly published on Node Package Manager (npm) as a malicious version after attackers gained access to a legitimate contributor’s GitHub account, exposing developers to the theft of cryptocurrency wallet credentials. Several security researchers…
Why Apple, Meta and Snap Want You to Stop Looking at Your Phone
The technology industry’s next computing platform may not fit in your hand. Instead, it could rest on your ears, sit on your face or hang around your neck. Apple is reportedly exploring AirPods equipped with cameras that would give…
OpenMandriva Accuses Former Contributor of Project Sabotage
OpenMandriva Linux is facing a serious internal security dispute after it said a former contributor abused administrative access to damage the project’s infrastructure. The alleged actions included deleting GitHub repositories and publishing an empty package that could have broken…
QIZ Security Raises $17 Million to Expand Cryptographic Security and Post-Quantum Readiness Platform
Israeli cybersecurity startup QIZ Security has raised $17 million in seed funding to fuel the development of its cryptographic security management solution and post-quantum cryptographic (PQC) readiness platform. The Israeli cybersecurity company has seen rising demand for its service,…
AI Agents Built to Detect Malware Can Be Manipulated Into Running It
AI agents capable of identifying malicious software can be manipulated by the AI Now Institute to execute it, according to new research. The proof-of-concept attack, known as “Friendly Fire,” demonstrates that autonomous AI coding agents, such as Claude Code…
GhostApproval Symlink Codes Could Run Malicious Codes in AI Coding Agents
Cyber security experts at Wiz discovered that a bug in six famous AI coding assistants allows a booby-trapped code project to silently take over a developer’s system. The assistant can ask access to edit one innocent-looking file, but the write…
Mount Royal University says hackers stole and deleted files following June cyberattack
Mount Royal University (MRU) has confirmed that threat actors stole data and deleted files after breaching the university’s network in a cyberattack that continues to affect recovery efforts weeks after the incident. In an update published on its website, the…
Fake Paysafe and Skrill SDKs on npm and PyPI Steal Developer Credentials
A coordinated supply-chain attack has compromised developers by distributing 17 malicious packages on npm and PyPI that impersonate legitimate SDKs for Paysafe, Skrill, and Neteller payment services. These packages were designed to silently exfiltrate sensitive credentials, including API keys,…
