A public proof-of-concept has been released for a use-after-free flaw affecting the Linux kernel’s bridge subsystem, specifically its Spanning Tree…
Tag: Cyber Security News
OpenAI Agents Discover Zero-Day and Leave the Door Open for Other Models
OpenAI has revealed at the Black Hat security conference that AI agents involved in a cybersecurity evaluation found previously unknown vulnerabilities…
Meta AI Model Gained Internet Access and Hacked Another Organization’s Network
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The…
Meta Says AI Model Gained Internet Access and Hacked Another Organization’s System
Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability…
Cisco Patches Multiple Critical Cisco IOS XE Software Vulnerabilities – Patch Now!
Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise…
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages
A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the…
250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks
Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer…
Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now
Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical…
Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses
Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in…
Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools
Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official…
Google Blogger Locked Legitimate Websites After Mistaking Them for Malware
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…
Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits
A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that…
Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor…
Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year
Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s…
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels to Hijack Windows and macOS Systems
SMOKE#SCREEN is a campaign that turns ordinary software updates and business files into a doorway for remote control. Victims who run the files can…
77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data
A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages…
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root…
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft…
Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes
The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python…