A new AI-agent attack technique called “Ghostjacking,” can trick coding agents into running attacker-controlled commands, changing cloud settings,…
Tag: Cyber Security News
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
A new remote access trojan called Abyssos lets attackers control infected Windows systems. The malware can steal credentials, collect files, and open…
LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD Pipelines
A LiteLLM compromise has raised concern over how a trusted AI software component can become an entry point into a network. The supply chain incident…
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being…
Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter…
New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp
A new phishing attack is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
New Phishing Attack Leverage SSL/TLS Certificates to Target High-value Brands Customers Via Whatsapp
A phishing operation is using web certificates and chosen web addresses to target customers of high-value brands through WhatsApp. The activity is…
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition
Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning…
Anthropic to Add Invisible Watermarks to All Claude AI Outputs
Anthropic has announced plans to add invisible watermarks and signed metadata to content created by Claude AI. The move follows the company’s decision to…
OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming
OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue…
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
A new “Pass-the-Passkey” family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security…
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s…
Claude Code Shifts Agent Security From Repeated Human Approval to Auto Mode
Anthropic is changing how Claude Code handles risky commands, moving away from constant human approval prompts and toward an automated safety classifier…
HP ThinPro TPM Disk Encryption Flaw Lets Attackers Extract LUKS Keys
A security researcher has disclosed a boot-chain weakness in HP ThinPro 8 and 9 that could allow attackers with physical access to a thin client to…
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
GitHub has expanded its malware detection capabilities beyond npm, providing developers with broader protection against malicious open-source packages.…
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed…
Windows WalletService Vulnerability Allows Attackers to Escalate Privileges – PoC Released
Microsoft has patched a Windows WalletService vulnerability that could let local attackers gain SYSTEM privileges, with a public proof of concept urging…
Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access
Red Hat has disclosed a critical privilege escalation flaw, tracked as CVE-2026-10090, affecting the Application Subscription controller in Red Hat…
Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers
A malicious Chrome extension masquerading as GoogleTranslate that can steal sensitive browser data, live-stream web sessions, and allow threat actors to…
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Android users are facing a fresh reminder that a familiar app-store listing can hide a financial threat. Researchers have observed malicious loaders on…