Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in…
Tag: Cyber Security News
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated…
Hackers Hide Malware Code Inside English Words to Infect Windows Users
A new Windows malware campaign is hiding malicious code inside ordinary English words, making the payload look less suspicious during analysis. The…
OpenAI Pauses AI Training Amid Concerns of New Model Potentially Discovering 0-Day Flaws
OpenAI has temporarily slowed frontier AI training after internal testing suggested that its upcoming Astra model may reach a critical cybersecurity…
Hackers Are Turning Claude, ChatGPT and Copilot Into Bait for Real Malware
Cybercriminals are increasingly using trusted artificial intelligence names as a shortcut to infect users with malware. Fake download pages, browser…
15 Malicious Firefox Extensions Abuse Cloudflare Workers to Exfiltrate Crypto Wallet Secrets
Firefox users are facing a coordinated campaign of malicious add-ons that masquerade as cryptocurrency wallets, themes, and simple browser tools. The…
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps
Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk…
New “Zombie Card” Flaw Lets Expired Visa Cards Make Contactless Payments
Security researchers have demonstrated that an expired credit card is not as dead as most cardholders believe. A new study from the University of…
Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts
Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could…
Critical Zimbra RCE Vulnerability Actively Exploited in the Wild
CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite. Tracked as…
AI Agent Hacks Snowflake GitHub Workflow and Reaches Internal Jira
An autonomous AI security agent built by Wiz Research has demonstrated how quickly a single overlooked line of shell code can cascade into a full…
T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network
T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese…
U.S. Agencies Warn of Hackers Actively Attacking Siemens S7 PLCs in Critical Facilities
The NSA, CISA, FBI, Department of Energy, and EPA issued a joint cybersecurity advisory on August 19 warning that threat actors are actively targeting…
Trusted Vendors Are Becoming Attack Paths: How US and EU Enterprises Can Reduce the Risk
A trusted supplier can become an attack path overnight. Large US and EU enterprises often rely on hundreds of vendors, giving attackers plenty of…
Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts
Hackers are pairing AI-generated phone calls with fake banking pages to take over customer accounts, even when multi-factor authentication is enabled. The…
Microsoft to End Support for Windows 11 24H2 Home and Pro Editions
Microsoft has issued a 60-day reminder that Windows 11 Home and Pro editions, version 24H2, will reach the end of updates on October 13, 2026. After that…
China-Nexus Hackers Disguise Malicious VHD as JPEG to Deploy QUICAgent Backdoor
A China-nexus cyber espionage campaign is using a convincing visual trick to reach Myanmar government and technology personnel. The attackers present a…
Microsoft 365 Service Degradation Disrupts Users Across South America
Microsoft is responding to a regional outage that may leave users in South America unable to use multiple Microsoft 365 services. The company is tracking…
CISA Adds Microsoft SharePoint Weak Authentication Vulnerability to KEV List
CISA added a critical Microsoft SharePoint authentication flaw to its KEV catalog after CVE-2026-55040 was confirmed in active exploitation, urging…
Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials
Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix…