FortiBleed credential-harvesting campaign, which has compromised more than 430,000 FortiGate firewalls worldwide, is directly feeding two active ransomware-as-a-service operations, INC Ransom and Lynx. SOCRadar’s Threat Research Unit identified an operator with access to FortiBleed infrastructure actively logged into negotiation panels…
Tag: Cyber Security News
Indian Govt Halts Meta’s WhatsApp Usernames Rollout Over Fraud Concerns
The Indian government has issued a formal notice to WhatsApp LLC (Meta), directing the platform to justify why regulatory action should not be taken against its newly announced “usernames” feature and instructing the company not to roll it out in…
Critical Cursor IDE RCE Vulnerabilities Enable Prompt Injection in Zero-Click
Two critical remote code execution (RCE) vulnerabilities in Cursor IDE, the AI-powered development environment used by more than half of Fortune 500 companies. Cato AI Labs has disclosed two flaws, dubbed ” DuneSlide, ” both of which carry a 9.8…
Apple ‘Hide My Email’ Vulnerability Exposes Users’ Real Email Addresses
Apple’s “Hide My Email” feature is currently affected by an unpatched vulnerability that allows attackers to discover the real email address behind an anonymized alias, according to researcher Tyler Murphy and independent tests by 404 Media. Apple’s Hide My Email,…
Anthropic’s Buffa Rust Library 0-Day Vulnerability Enables DoS Attack
Anthropic’s Rust-based protobuf implementation, buffa, has been found vulnerable to a zero-day denial-of-service (DoS) condition caused by unbounded heap allocation on attacker-controlled input. The flaw, now tracked as CVE-2026-55407 and GHSA-f9qc-qg88-7pq5, affects buffa and connectrpc versions before 0.8.0 and has…
Critical Multiple Adobe ColdFusion Vulnerabilities Enables Arbitrary Code Execution Attacks
Adobe has released an urgent security update for ColdFusion 2025 and 2023 to fix multiple critical vulnerabilities that could allow arbitrary code execution, privilege escalation, arbitrary file read, and security feature bypass. The issues are rated Priority 1, meaning administrators…
A Weaponized Google Ad Install Malicious Claude Code to Hijack Entire macOS
A sponsored Google ad impersonating Anthropic’s Claude Code CLI has been caught delivering “MacSync Stealer,” a macOS credential harvester that also silently trojans Ledger Live and Ledger Wallet apps to steal crypto seed phrases. The campaign was discovered and fully…
Attackers Weaponizing Trusted Windows Drivers to Kill AV and EDR Processes
Attackers are increasingly abusing trusted Windows drivers to turn off antivirus (AV) and endpoint detection and response (EDR) tools, using a technique known as Bring Your Own Vulnerable Driver (BYOVD). Once considered niche, BYOVD has rapidly become a standard component…
Multiple Citrix NetScaler ADC and Gateway Vulnerabilities Enables DoS and Memory Overflow Attacks
Multiple high-severity vulnerabilities have been identified in Citrix NetScaler ADC and NetScaler Gateway, exposing affected systems to denial-of-service (DoS) and memory overflow attacks. The issues, tracked under CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474, were disclosed in a security bulletin…
How a US Automotive Manufacturer Closed Its Supplier Security Gap and Doubled SOC Triage Speed
For a US automotive manufacturer that depends on more than 200 active vendors, the steady stream of supplier files coming into its environment had turned into both a security exposure and a rising operational cost. The strain is felt acutely…
Chrome Update Fixes 382 Vulnerabilities, Including 15 Critical Ones – Update Now!
Chrome 151’s latest stable-channel update delivers patches for 382 security vulnerabilities, including 15 critical bugs that can be weaponized for remote code execution and full browser compromise if left unpatched. Google is rolling this update out for Windows, macOS, Linux,…
U.S. Lifts Export Controls on Claude Fable 5 and Mythos 5
The U.S. Department of Commerce has formally withdrawn export control restrictions on Anthropic’s Claude Fable 5 and Mythos 5 AI models, ending an 18-day standoff that had blocked global access to the company’s most advanced systems. In a letter dated…
Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication
The Apache Software Foundation has disclosed two vulnerabilities affecting Apache Tomcat that could allow attackers to bypass authentication and security constraints protecting web applications. The flaws, tracked as CVE-2026-55957 and CVE-2026-55956, impact multiple major versions of the widely deployed servlet…
Microsoft Teams’ New Feature Blocks Bots from Joining Meetings
Microsoft has rolled out a new bot protection capability in Microsoft Teams that gives IT administrators and meeting organizers greater control over external bots attempting to join meetings, a move designed to address growing privacy and security concerns around AI-powered…
Anthropic’s Claude Code Reportedly Uses Hidden Code to Detect Chinese Users
A Reddit disclosure has ignited a serious debate about developer trust and covert surveillance, alleging that Anthropic embedded undisclosed detection logic inside its Claude Code CLI tool, specifically targeting users in China or those routing traffic through Chinese AI lab…
New BioShocking Attack Allows Attackers to Trick AI Browser and Leak Credentials
A newly disclosed attack technique dubbed “BioShocking” is raising concerns across the cybersecurity community after researchers demonstrated that AI-powered browsers can be manipulated to leak sensitive data and bypass built-in safety controls. Security researchers at LayerX revealed that attackers can…
False Positive or First Sign of a Breach? How Tier 1 SOC Analysts Can Tell the Difference Faster
Imagine a Tier 1 analyst receiving an alert: an employee’s laptop has connected to an unfamiliar domain. The detection is not dramatic. No ransomware note. No obvious malware verdict. No endpoint isolation. Just a domain, an IP address, a timestamp, and a medium-severity…
Hackers Hijack WhatsApp Web Sessions to Launch CEO Fraud Through DLL Sideloading
A new breed of executive impersonation attack is making rounds across Indian enterprises, and it is far more technical than the typical CEO fraud most organizations have prepared for. This campaign, dubbed the “Boss Scam,” blends social engineering with a…
Hackers Use SystemBC Malware to Hide C2 Traffic and Maintain Persistent Access
A cyberattack tool that quietly turns victim computers into tunnels for criminal traffic has been gaining ground across enterprise networks. Security researchers have linked it to some of the most destructive ransomware operations in recent years. Known as SystemBC, this…
Bing Search for ‘ManageEngine OpManager’ Delivers Akira Ransomware
A simple Bing search for a popular IT tool turned into a full-scale ransomware attack. Threat actors abused search engine optimization (SEO) poisoning to push a fake download link into Bing search results, tricking IT administrators into installing malware disguised…