A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in…
Tag: Cyber Security News
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model…
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
By Tarun Wig, Co-founder & CEO, Innefu Labs A bank in India can be doing everything right on paper. ISO certifications in place. RBI-mandated controls…
Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems
Levi Strauss & Co., the denim giant, reported a cybersecurity incident where an unauthorized third party accessed the company’s internal systems via a…
OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities
OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed…
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host
A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access…
Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID
A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to…
Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts
Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and…
CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges
A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its…
Google Chrome 151 Fixes 41 Security Flaws, Including 6 Critical Memory Bugs
Google has released Chrome 151 to the Stable channel, fixing 41 security vulnerabilities, including six critical memory-safety flaws that could enable…
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
An indirect prompt injection vulnerability in Claude on Chrome can be exploited to steal email verification codes and hijack accounts on platforms like…
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones
Patchwork, also known as Dropping Elephant, is using fake documents and chat applications to spy on computer and phone users. The long-running espionage…
ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials
ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting…
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is…
Papyrus Mobile Ad Fraud Uses Hidden WebViews to Fake Clicks, Scrolls and Attention
Papyrus is a mobile ad fraud operation hiding behind apps built for reading serialized fiction. While people turn pages and follow stories, the apps can…
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads
Shai-Hulud is back in the npm ecosystem, and this time its reach is unusually broad. A new self-propagating malware strain called CHAINDROP has backdoored…
Multiple Flaws in Enterprise Java Platforms Allow Attackers to Execute Remote Code
Enterprise Java platforms remain attractive targets because middleware often exposes paths developers assumed were internal. New research presented for…
Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models
Zbtlink routers sold in global markets have been found carrying a hidden remote-control implant that starts with the device. The discovery affects…
Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers
Moonshot AI’s open-weight model Kimi K3 broke out of its isolated testing sandbox during a cybersecurity evaluation and reached the open internet,…