North Korean threat actors behind the Contagious Interview campaign have been observed persistently targeting software supply chains by distributing more than 100 malicious packages and browser extensions. Researchers note that the PolinRider campaign is targeting software developers and those…
Category: CySecurity News – Latest Information Security and Hacking Incidents
New Bad Epoll Bug Impacts Android and Linux, Allows Root Access
A recently found Linux kernel vulnerability called ‘Bad Epoll’ (CVE-2026-46242) allows an ordinary person without any special privilege to take complete command of a device as a root. This has impacted Linux systems, Android, and servers, and a patch is…
JadePuffer Uses AI to Streamline End to End Ransomware Operations
Researchers have discovered the first ransomware intrusion conducted almost entirely by an autonomous large language model (LLM) agent, further demonstrating how generative AI and cybercrime are convergent. Sysdig researchers were able to detect the campaign by analyzing an attack…
Massive Azure CLI Password Spray Campaign Targets Microsoft 365, Over 81 Million Login Attempts Detected
Cybersecurity company Huntress has uncovered a large-scale password spray campaign targeting Microsoft 365 environments through the Azure CLI, resulting in millions of malicious login attempts and multiple account compromises. According to the company, between June 12 and June 21,…
AI-Driven Software Development Demands a New Approach to Security Audits
Artificial intelligence is rapidly reshaping how software is built, enabling developers to generate code, automate repetitive tasks and accelerate application development. While these tools are helping organizations improve productivity, cybersecurity experts warn that they are also introducing new security…
Anubis Ransomware Gang Attacks Again, Exploit Remote Access
Hackers linked with Anubis ransomware operation were found abusing the Citrix Bleed 2 (CVE-2025-5777) flaw to find initial access. According to Arctic Wolf, the techniques vary among different affiliates, and few patterns surfaced in tradecraft via authentic Remote Management and…
Apple Expands AI in iOS 27 with Smarter Everyday Features Beyond Siri
Apple is expanding its artificial intelligence strategy beyond Siri with iOS 27 by integrating AI across its apps and services instead of relying on a standalone chatbot. The new features are designed to simplify everyday tasks through automation while…
Google Targets NetNut Residential Proxy Network Operating Across Two Million Devices
Several international authorities have coordinated operations to disrupt the infrastructure behind a large residential proxy network, also known as Popa, after Google dealt a significant blow to one of the internet’s largest residential proxy ecosystems. Through the action, which…
MSG Data Breach: Hackers Leak Facial Recognition Records of 26 Million Visitors
A massive data breach at Madison Square Garden has exposed the facial recognition and personal records of millions of visitors, sparking outrage and legal action. The cybercrime group ShinyHunters leaked 45 gigabytes of stolen data after the arena’s parent…
Nissan Confirms Employee Data Breach Following Oracle PeopleSoft Zero-Day Cyberattack
Nissan has confirmed that it fell victim to a third-party cyberattack after being targeted as an Oracle PeopleSoft user, making it the latest company to suffer an attack due to a yet-revealed vulnerability. The breach is currently under investigation,…
Google Cripples NetNut Proxy Network Spanning 2 Million Devices
Google has delivered a major blow to NetNut, one of the world’s largest residential proxy networks, by crippling its ability to route malicious traffic through millions of compromised home devices. The operation, conducted in coordination with the FBI, Lumen,…
BioSchocking Attacks Tricked AI-powered Browsers into Data Theft
A new prompt injection termed “BioShocking” can manipulate AI-based browsers into treating malicious actions as a video game, and give away your login credentials. The technique was discovered by experts at security firm LayerX. The experts tricked six AI-powered browsers…
U.S. Secures Extradition of 19-Year-Old Linked to Scattered Spider
US authorities have intensified their pursuit of individuals linked to the financially motivated hacking collective Scattered Spider, and the extradition of a 19-year-old suspect marks another significant development. Peter Stokes, who is a dual citizen of the United States and…
Researchers Warn of Unpatched Argo CD Flaw That Enables Cluster Takeover
Organizations using Argo CD to automate application deployments on Kubernetes are being urged to review their network configurations after security researchers disclosed an unpatched vulnerability that could allow attackers to execute arbitrary code on the platform’s repo-server component and…
Accenture Buys Cybersecurity Firms Dragos, runZero, NetRise for $4.18 Billion
In a landmark move to fortify its cybersecurity capabilities, Accenture has announced a $4.18 billion deal to acquire a majority stake in industrial cybersecurity leader Dragos, alongside full ownership of asset intelligence firm runZero and device security specialist NetRise.…
Hackers Breached Kubota, Employee Data Compromised
Kubota North America Corporation revealed that threat actors compromised its network systems and accessed few resources for over a month in the beginning of 2026. After an investigation of the breach, the organization discovered that between March and April, the…
WhatsApp Tests New Android Chat Backup Management Feature to Improve Google Drive Storage Control
Managing WhatsApp backups on Android might become significantly easier in the future as the messaging platform prepares new solutions to give users more control over their data. The upcoming update will allow people to organize and delete old backups,…
ClickFix Investigation Exposes API-Driven Malware Across 3,000 Live Payloads
A growing number of ClickFix campaigns are advancing from simple social engineering operations into highly orchestrated malware delivery operations supported by dynamic infrastructure. A recent study analyzing nearly 3,000 ClickFix payloads reveals that attackers are utilizing API-based delivery systems…
UAE Becomes First Arab Nation to Ban Social Media for Children Under 15
The United Arab Emirates has become the first Arab nation to impose a comprehensive ban on social media use for children under the age of 15, marking a significant milestone in digital child protection. Announced in mid-June 2026 through…
Anthropic to Restore Access to Claude Fable 5 After U.S. Lifts Export Controls
Anthropic is preparing to restore access to its Claude Fable 5 artificial intelligence model after the U.S. Department of Commerce lifted export controls that had temporarily restricted deployment of the company’s most advanced AI systems. The company announced on X…
