ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386,…
Tag: Cyber Security News
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required. Security researchers…
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected system files and seize host root privileges, even on systems running SELinux in…
A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results
A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the appearance of the widely used Newtonsoft.Json library while carrying code designed to alter…
Russian Intelligence Hijacks IP Cameras to Monitor Weapons Deliveries to Ukraine
Russian intelligence services have been accused of turning everyday internet-connected cameras into surveillance tools for tracking weapons deliveries to Ukraine. The campaign shows how a device installed for basic security can become a source of military intelligence when it is…
Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files
A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files. Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple…
SolarWinds Patches 15 Critical Serv-U Flaws That Could Hand Attackers Root Access
SolarWinds has released important security updates for its Serv-U file transfer software, addressing 15 vulnerabilities that could allow attackers to gain elevated privileges and, in some cases, execute code with root user access. These fixes were delivered in Serv-U version…
Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
Royal ransomware turned ordinary Windows compromises into enterprise-wide crises by pairing a phishing foothold with fast domain takeover. In incidents reviewed by responders, the operators used Qbot to gain a presence and then expanded their reach before deploying encryption. The…
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims
The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July…
Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
Zimbra fixed a critical Zimbra Collaboration Suite (ZCS) command injection flaw in version 10.1.20 that could allow attackers to abuse the SNMP service and execute arbitrary commands on affected servers. The flaw affects environments where SNMP notifications are enabled, potentially…
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…
Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks
Oracle has released its July 2026 Critical Patch Update (CPU), shipping 1,449 security patches that collectively remediate more than 1,200 vulnerabilities across databases, middleware, cloud services, and enterprise applications, in what is now the largest CPU in the company’s history.…
New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies
NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating proxy infrastructure. The framework came to light when a single Pastebin post was…
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate…
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud…
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to…
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security…
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the…
GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews. The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems. The attackers…
OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
Hugging Face has disclosed a security incident that security researchers are calling a watershed moment for AI safety: an autonomous AI agent, built on OpenAI models, independently discovered and chained multiple vulnerabilities, including a zero-day, to breach Hugging Face’s production…