A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by…
Tag: Cyber Security News
CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft Internet Key Exchange vulnerability, tracked as CVE-2026-33824,…
MacSync Stealer Hides Behind 30+ Domains While Stealing Passwords and Sensitive Mac Data
MacSync Stealer is expanding the risk facing Mac users by turning everyday web browsing and Terminal activity into a route for password theft. The…
Ransomware Hackers Pose as Recovery Firm and Demand Up to $60,000
Ransomware victims are facing a new kind of pressure campaign. Instead of receiving another demand from the attackers who stole their data, some companies…
Hundreds of Leaked Stripe Merchant Keys Expose Payment and Payout Capabilities
Hundreds of leaked Stripe merchant keys have exposed a serious risk for online businesses and their customers. The collection contains active credentials…
Windows Defender Update for 0-day Vulnerability Breaks Virus Scans
Microsoft Defender has been aborting Quick, Full, and Offline virus scans after a cluster of Security Intelligence updates reached Windows PCs on August…
Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the Wild
Hackers are actively abusing a flaw in macOS Screen Sharing to take root-level control of a small number of devices. The attacks turn a built-in…
Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps
Mac users searching for help with Claude Code are being lured into a malware campaign that turns a routine installation task into a full device…
RAVEN Tool Exfiltrates Entire Elasticsearch Databases and Maintains Access After Password Rotation
A newly detailed offensive security tool called RAVEN shows how a compromised Elasticsearch environment can become a data-loss incident with persistent…
Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability
Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update, addressing flaws across its enterprise software portfolio.…
Cl0p Hackers Exploit PTC Windchill Flaw to Steal Passwords and Sensitive Company Data
Cl0p, also tracked as Cl0P, has returned with a campaign aimed at PTC Windchill servers, putting engineering files, passwords, and company records at…
Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks
A binary planting vulnerability in the Cursor IDE that lets a malicious git.exe file, placed at the root of a repository, run automatically the moment a…
BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges
BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with…
CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Broadcom VMware vCenter vulnerability, tracked as CVE-2026-59310, to its…
Google Fixes Two Critical Chrome Flaws in WebGL and Dawn — Update Your Browser
Google has released a new Chrome Stable channel update that fixes two critical security vulnerabilities affecting graphics-related components. Users…
Claude Can Now Send Emails in Gmail and Manage Files in Google Drive
Anthropic has moved Claude out of the draft-only inbox and into live Google accounts. In an August 18, 2026 post, the company said users can ask Claude to…
Critical Microsoft Copilot CoSnitch Vulnerability Lets Attackers Steal Sensitive Data With One Click
A critical vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and nicknamed CoSnitch, lets attackers silently siphon sensitive data…
Irregular Pushes Stronger Containment Standards for Secure Frontier AI Cyber Evaluations
Irregular has detailed an investigation into an AI cyber-evaluation incident in which internet access unintentionally allowed models to interact with…
French Tax Authority Data Breach Exposes 600,000+ Users’ Personal Tax-Related Data
France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized…
CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human…