A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review…
Tag: Cyber Security News
SimpleHelp Authentication Bypass Vulnerability Exploited in the Wild to Deploy TaskWeaver Loader
A critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software is being actively exploited in the wild. This enables attackers to deploy advanced malware, including a newly identified loader, TaskWeaver, and an information-stealing tool, Djinn Stealer. Security…
Multiple WolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Cyberattacks
Multiple newly disclosed vulnerabilities in the wolfSSL embedded TLS library expose billions of servers and Internet of Things (IoT) devices to potential certificate forgery, remote code execution, and denial-of-service attacks if left unpatched. These flaws undermine core trust mechanisms in…
PoC Released for NTLM Reflection Bypass Flaw that Enables SYSTEM Access on Windows Server
A working proof-of-concept (PoC) exploit has been released for a new NTLM reflection bypass flaw that enables SYSTEM-level access on Windows Server 2025, raising fresh concerns about the resilience of Microsoft’s authentication hardening. The vulnerability, tracked as CVE-2026-24294, shows that…
GitHub Advisory Database Hits Record Volume as Vulnerability Reports Surpass Review Capacity
GitHub’s Advisory Database reached an all-time high in May 2026, publishing 1,560 reviewed security advisories, more than five times its typical monthly output. Despite this milestone, the platform still struggled to keep pace with a rapidly expanding volume of vulnerability…
New Windows Backdoor Mistic Enables In-Memory Code Execution and Credential Theft
A newly identified Windows backdoor called Mistic has been quietly making its way through enterprise networks since April 2026, giving attackers persistent, low-profile access that is extremely difficult to detect. The malware has been spotted targeting organizations across the insurance,…
X Launches Hosted MCP Servers to Connect Cursor, Claude, and Other AI Tools
X (formerly Twitter) has officially launched hosted Model Context Protocol (MCP) servers, enabling AI development tools such as Grok Build, Cursor, and Claude Desktop to seamlessly connect with the platform’s API and documentation. Announced on Tuesday, the move positions X…
Mustang Panda Abuses Zoho WorkDrive for Command-and-Control and Data Exfiltration
A China-aligned cyber espionage group known as Mustang Panda has been caught running two simultaneous attack campaigns against Indian government and energy targets, using a trusted cloud storage service as its hidden command center. The group deployed newly developed malware…
Synology MailPlus Server Vulnerabilities Allow Attackers to Trigger DoS Attacks
Synology has released a critical security advisory addressing multiple vulnerabilities in its MailPlus Server package that could allow attackers to execute denial-of-service (DoS) attacks, access internal services, and read or modify arbitrary files. The vulnerabilities affect multiple versions of MailPlus…
Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals
A fake browser extension disguised as the popular AI search tool Perplexity AI has been caught quietly capturing users’ real-time search inputs and browser signals, raising serious concerns about how easily trusted brand names can be used against ordinary users.…
Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking
Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers.…
Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks
Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The attack stems from…
U.S. Seizes Hundreds Domains Used to Stream World Cup Matches Illegally
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 domains used to illegally stream FIFA World Cup 2026 matches, marking a significant crackdown on global digital piracy networks. The operation, conducted under “Operation Offsides,” targeted websites…
New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems
Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that shows how a completely clean-looking GitHub repository can trick AI-powered coding agents like Claude Code into silently opening a reverse shell on a developer’s machine, without…
EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses
EvilTokens can keep serious account-takeover activity out of your SOC’s view by relying on “ghost” code that only surfaces after the browser decrypts it. Because of this, analysis that looks only at the static URL can overlook the part of the…
WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers
WhatsApp introduces a new privacy update that lets users connect using unique handles, eliminating the need to share phone numbers with strangers or new group members. Earlier, we detailed that WhatsApp is preparing to roll out a long-anticipated username feature.…
Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code
A critical security vulnerability in Google’s Gemini CLI has been disclosed, allowing attackers to execute arbitrary code in certain CI/CD environments, particularly GitHub Actions workflows. The issue, tracked as CVE-2026-12537, impacts multiple versions of the Gemini CLI and its related…
Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File
Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file. The vulnerability, tracked as CVE-2025-60727, affects multiple versions of Microsoft Office and underscores the continued risk posed by…
Critical Dell Wyse Vulnerabilities Enable Remote Code Execution Attacks
Dell Technologies has released a critical security advisory addressing multiple vulnerabilities in its Wyse Management Suite (WMS), warning that attackers could exploit these flaws to execute arbitrary code on affected systems. The vulnerabilities affect Dell Wyse Management Suite versions before…
Hackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks
Threat actors are actively exploiting CVE-2026-46817, a critical unauthenticated remote takeover vulnerability in Oracle E-Business Suite (EBS), with live attack activity captured across honeypot infrastructure over the weekend of June 27–28, 2026. CVE-2026-46817 is a critical-severity flaw residing in the…