Global malware activity climbed sharply over the past week, with remote access trojans (RATs), information stealers, and loaders all posting significant…
Tag: Cyber Security News
Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram
Malicious extensions are turning a routine developer task into a route for theft. A package named Solidity Pro, promoted as a useful tool for Solidity…
Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage
CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root…
Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption
Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and…
Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach
Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and…
Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose…
Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft. The group has turned memory analysis software into a…
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS
Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A…
Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic…
Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into…
Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows…
Hackers Distributing Malicious VBS/PowerShell RAT Chain Via Multiple DuckDNS Hosts
A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic…
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval
RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira,…
Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results…
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent…
Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts
Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than…
Claude-Powered OpenClaw AI Agent Exploits Gym API to Steal a Workout Slot
An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it…
Microsoft to Launch New Security Detection Report in Teams
Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to…
Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories
This week’s roundup covers active exploitation of Apache Tomcat and SonicWall SMA, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able…
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked…