SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.…
Tag: Cyber Security News
SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner
A new SSH bot has been caught quietly logging into Linux systems, profiling their CPU, GPU, and memory, and then walking away without dropping any visible…
DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers
A Chinese-speaking threat actor used an AI-driven agent to search for vulnerable internet-facing servers and begin attacks with little direct human input.…
ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans
Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify…
CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not
By John Grancarich, EVP, Head of Defense & Intelligence, Fortra The recent pause affecting the implementation of Cybersecurity Maturity Model…
FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
The U.S. State Department, FBI, and allied governments including Japan, Canada, Germany, Australia, the United Kingdom, and the Republic of Korea have…
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency…
Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities
Google is expanding the use of artificial intelligence (AI) agents across the Chrome security lifecycle to identify source code weaknesses, test patches,…
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be…
Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows attackers to bypass…
Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities
The Stable channel has been updated to Chrome version 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, with the rollout taking place…
New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances
GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems and has…
Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion
Analog Devices, Inc., a leading U.S. semiconductor manufacturer specializing in analog, mixed-signal, and digital signal processing technology, has…
Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE
Attackers are exploiting a significant portion of vulnerabilities even before defenders receive a published CVE (Common Vulnerabilities and Exposures). In…
New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances
A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on…
Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT
AtlasRAT is being delivered through a fake Flash Player installer that looks harmless but can give attackers remote control of a Windows computer. The…
Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps
A new fraud campaign is targeting Android banking users through convincing phone calls that impersonate N26 support staff. The attack begins as voice…
Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem Restrictions
The Node.js project has released important security updates addressing 11 vulnerabilities across its active branches: 22.x, 24.x, and 26.x. The updates…
Developer Claims Claude Opus 5 Wiped an Entire Production Database in Minutes
A developer has reported that Anthropic’s Claude Opus 5, running in Ultracode mode, accidentally wiped an entire production database in roughly ten…
Inside the Cybercrime Platform That Turns Helpdesk Calls Into Enterprise Account Takeovers
Voice phishing is no longer limited to a convincing phone call and a fake sign-in page. A newly examined criminal platform called Work Panel brings target…