The U.S. Department of Justice has unsealed a 14-count superseding indictment against 17 alleged members of the Iran-based Mabna Institute, accusing them…
Tag: Cyber Security News
OpenAI Offers Zero Data Retention for Frontier AI Models With Private Safety Processing
OpenAI has announced Zero Data Retention for eligible API customers using its frontier AI models, alongside a new Private Safety Processing system…
Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers
A critical vulnerability in Spring Security’s embedded UnboundID LDAP server can allow remote attackers to gain administrative access to exposed in-memory…
Google Chrome 151 Chromoting Flaw Allows Attackers to Execute Malicious Code Remotely
Google has released Chrome 151 Stable, fixing seven security vulnerabilities, including a critical use-after-free flaw in Chromoting that could…
China-Linked Spy Campaign Uses Five New Malware Families Against Central Asian Governments
Central Asian government bodies have been targeted in a cyberespionage operation using a compact but varied set of remote access tools. The activity,…
Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads
Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were…
Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux
A security researcher has successfully reverse-engineered Apple’s private Find My People protocol, demonstrating that a Linux machine can register with…
Microsoft Entra ID Remote Code Execution Vulnerability Exploited in the Wild
Microsoft has confirmed that a critical remote code execution flaw in Entra ID, its cloud-based identity and access management platform, has already been…
Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations,…
AWS Shows How to Stop a Hijacked AI Agent From Reading Data the User Cannot Access
Enterprises are racing to deploy AI agents that pull from databases, document repositories, SaaS platforms, and internal knowledge bases to automate…
CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users
A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on…
Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
A critical security flaw in NASA/JPL’s open-source AMMOS Instrument Toolkit GUI (AIT-GUI) could let an unauthenticated attacker send live commands to…
Popular Rust Packages With 244M Downloads Compromised to Run Malware
A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec, were hijacked to silently deliver…
Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets
Cybercriminals are turning AI agents into a new route for malware delivery. A campaign targeting OpenClaw, an open-source platform that lets AI agents…
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted…
Zyxel Patches Command Injection Flaw in 18 Access Points Allowing Root OS Command Execution
Zyxel has released firmware updates for a high-severity command injection vulnerability, tracked as CVE-2026-6837, affecting 18 wireless access point…
Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments
A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows…
New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones
A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in…
Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes
Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs. The campaign combines…
CyberPanel Pre-Auth RCE Chain Lets Attackers Gain Server Shell via AI Scanner Flaws
Security researchers have disclosed a critical pre-authentication RCE chain in CyberPanel that could let attackers gain a shell on vulnerable hosting…