A new phishing campaign is targeting job seekers by posing as recruiters from recognizable brands. The scheme uses fake career pages and worded emails to trick people into handing over Gmail login credentials. What makes this campaign notable is not…
Tag: Cyber Security News
Microsoft Confirms Windows 11, 26H2 Comes With Change in Backup Policy
Microsoft has confirmed a significant change to its Windows settings backup policy with the upcoming release of Windows 11 version 26H2, marking a shift toward improved system resilience and recovery capabilities. According to Microsoft, the Windows settings backup policy will…
OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt
A newly disclosed vulnerability in the OpenAI Codex desktop application for macOS could allow attackers to exploit indirect prompt injection techniques to exfiltrate sensitive data, according to a recent entry in the GitHub Advisory Database. Tracked as CVE-2026-14898, the issue…
Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT
Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT. The campaign blends social engineering with legitimate remote support software, making it…
Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework
A new Iranian-linked hacking group has been caught abusing everyday IT tools to slip malware onto Israeli networks. Researchers have named the group Cavern Manticore, and its latest campaign shows how creative attackers have become at hiding in plain sight.…
16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory
A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed “Januscape,” exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained…
Tenda Authentication Backdoor Grants Attackers Full Administrative Access
A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10,…
Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking Group Member
A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint filed in the Northern District of Illinois. Peter Stokes, 19, a dual U.S.–Estonian citizen who allegedly used…
Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access
BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems. The issues are tracked under Advisory ID…
Windows Device Identifier Used to Arrest Scattered Spider Hacking Group Member
A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint filed in the Northern District of Illinois. Peter Stokes, 19, a dual U.S.–Estonian citizen who allegedly used…
Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files
A critical security flaw has been discovered in the fast-mcp-telegram package that could allow remote attackers to access sensitive Telegram session data and perform unauthorized actions. The vulnerability, tracked as CVE-2026-52830 , affects all versions up to 0.19.0 and has been fixed…
Top 10 Best Next-Generation Firewall (NGFW) Solutions in 2026
If you’re shortlisting the best next-generation firewall for 2026, Palo Alto Networks’ PA-Series is our top overall pick for its App-ID application control and machine-learning threat prevention, while Fortinet FortiGate delivers the strongest price-to-performance for most mid-market and distributed networks.…
The Gentlemen Ransomware Uses 21 Remote Execution Techniques to Encrypt Entire Networks
A new ransomware strain called The Gentlemen has emerged as one of the more aggressive threats tracked this year, combining strong encryption with a self-spreading worm engine that can take down an entire corporate network from a single infected machine.…
Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens
A security flaw in how developers implement Google’s Gemini Live API allows attackers to hijack browser-based AI voice sessions, override system prompts, and trigger unauthorized code execution all through a token misconfiguration that traces back to Google’s own reference implementation.…
Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page
A new phishing technique is tricking users into handing over their Microsoft account tokens without a fake website in sight. Attackers are exploiting a legitimate Microsoft authentication feature to steal access to email, files, and chat messages. The method works…
OpenSSH 10.4 Released with Multiple Security Fixes and New Features
OpenSSH 10.4 launched on July 6, 2026, delivering a batch of security patches, protocol hardening, and early post-quantum cryptography support, available through mirrors listed on the official OpenSSH site. OpenSSH 10.4 Security Fixes The release addresses several vulnerabilities across core…
SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in Live ValleyRAT Campaign
A new strain of remote access malware is quietly moving through corporate networks, and it does not behave like anything defenders have seen from this threat group before. The malware, tracked as ValleyRAT, is deployed by a hacking group known…
RedLine C2 Pivot Reveals Seven Fraudulent Domains Used in Maritime Phishing Attacks
A single leaked command and control server ended up unraveling an entire phishing operation aimed at the maritime shipping world. What started as a routine look at RedLine Stealer traffic turned into the discovery of seven fake domains built to…
Multiple ModSecurity Vulnerabilities Allow Attackers to Bypass Firewall Rules
Multiple vulnerabilities have been disclosed in OWASP ModSecurity, a widely used open-source web application firewall (WAF), allowing attackers to bypass security rules under specific conditions. The flaws, tracked as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15 and have…
Moody Bible Institute Data Breach Exposes 2.3 Million Users’ Personal Data
Moody Bible Institute has confirmed a significant data breach after threat actors linked to the ShinyHunters extortion group published personal information belonging to over 2.3 million individuals. The exposed dataset includes donors, supporters, students, and alumni associated with the institute.…