The US Department of Defense (DoD) has decided to suspend the implementation of the cybersecurity maturity model certification (CMMC) second phase on a temporary basis. The DoD will conduct a 60-day review before continuing with the implementation of the…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
Researchers Find Claude for Chrome Flaws That Could Let Malicious Extensions Trigger Sensitive Google Tasks
Researchers at Manifold Security have disclosed two security weaknesses in Anthropic’s Claude for Chrome extension that could allow another browser extension with access to the Claude website to trigger predefined AI-powered actions involving a user’s Gmail, Google Docs and Google…
RabbitMQ Flaw Exposes OAuth Secrets, Risks Full Broker Takeover
A serious vulnerability in RabbitMQ is threatening enterprise messaging systems by allowing attackers to steal OAuth secrets and take full control of brokers. Tracked as CVE-2026-57219, the flaw has a CVSS score of 8.7 and affects popular RabbitMQ versions…
Japan’s Largest Taxi Service Goes Offline After Cyberattack
Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure. The incident happened last week and impacted business operations such as the company’s taxi dispatch…
CrashStealer macOS Malware Uses Apple-Notarized App to Evade Security Checks
CrashStealer, a new macOS information-stealing malware named for Apple’s Mac operating system, bypasses built-in security protections by using an Apple notarized application, demonstrating a growing trend of malicious actors utilizing legitimate software verification mechanisms in order to target Apple users. …
How the Apple Copy-Paste Scam Can Give Attackers Remote Access to Your Mac
Apple users are being urged to exercise caution when following troubleshooting instructions found online after cybersecurity experts underlined a growing social engineering tactic that tricks victims into pasting malicious commands into the macOS Terminal application. Rather than exploiting a…
GoDaddy Challenges Indian Court Order Over Domain Privacy and Internet Governance Rules
A legal battle in India over online fraud could have major implications for privacy and regulation of the internet around the globe, as domain name registrar Go Daddy takes exception to a Delhi High Court ruling that would impose…
UK Warns Parents: Limit Online Sharing of Kids’ Photos Amid AI Abuse Risks
UK authorities have issued urgent warnings to parents about sharing children’s photos online, as AI tools increasingly enable digital abuse and exploitation. The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) say that ordinary images of kids…
Anthropic Delays Claude Fable 5 Usage Credit Requirement Until July 19
A number of Anthropic’s flagship AI model, Claude Fable 5, has been extended to eligible paid subscribers until July 19, 2026 for free access. This extension provides customers with another week of access while the company continues to expand…
Microsoft and Google Remove ModHeader After Finding Dormant Collector
ModHeader is a famous header-editing extension with over 1.6 million installs across Microsoft’s Edge and Google’ Chrome browser. Google and Microsoft remove the collector Experts discovered a secret browsing-history collector built into its official store variant, and have withdrawn the…
Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer
Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…
Counterfeit USB Drives Spread China-Linked Virus in Japan’s Military
Counterfeit USB flash drives supplied to Japan’s Ground Self-Defense Force (JGSDF) in March 2024 spread a China-linked computer virus across secure military networks for nearly a year before the breach was finally detected. The incident, first reported by Japan’s…
Zimbra Urges Immediate Update to Fix Critical Classic Web Client XSS Vulnerability
Zimbra has released a security update to address a critical vulnerability in the Zimbra Classic Web Client that could allow malicious actors to compromise user accounts and execute unauthorized code. The company recommends that customers install the latest update…
Authentic GitHub Repository Can Trick AI Agents Into Installing Malware
An agentic AI coding tool built for making a GitHub repository and cloning could launch a malicious payload that stays hidden to AI agents, human reviewers, and security scanners. Malicious payload with no exploit code Experts from Mozilla Zero Day…
Operation Endgame Disrupts Global Cyber Crime Assembly Line
Private companies and international authorities have disrupted a malicious “assembly line” that let hackers steal millions of login details and theft of $47 million in ransom payments via extortion. The operation aimed at catching two tools that are used in…
Centre Plans New Cybersecurity Norms for Electric Two- and Three-Wheelers to Address Battery Tampering Risks
The Central government is preparing to introduce new cybersecurity measures aimed at preventing unauthorised tampering with the batteries of electric two-wheelers and three-wheelers. The proposed regulations are expected to mandate stronger software security standards for electric scooters and e-rickshaws,…
India Orders Telegram to Crack Down on Pirated Movies and OTT Content, Seeks Compliance Report
Ministry of Information and Broadcasting (MIB) has directed the messaging platform Telegram to take down the pirated films, OTT content and other audio-visual material uploaded on it. It also called upon the company to put in place measures to…
Google Sent Earthquake Warnings Before Venezuela Tremor Reached Millions
In Venezuela, millions of Android users received earthquake alerts on their phones just minutes before two devastating 7.1 and 7.5 earthquakes struck, highlighting the increasing importance of smartphone-based early warning systems for disaster response. Google reported that its Android Earthquake…
JadePuffer: First AI-Agent Ransomware Automates Entire Attack
Security researchers have identified JadePuffer as the first ransomware operation conducted entirely by an AI agent, marking a watershed moment in automated cyberattacks. Discovered by cloud security firm Sysdig, this incident demonstrates how large language model (LLM) agents can…
Meta Faces Privacy Questions After Employee Data Exposure Report
After sensitive employee information was reportedly made available throughout the organization, Meta has suspended an internal employee monitoring initiative intended to assist in the development of artificial intelligence systems. Initially introduced in April, the Model Capability Initiative was intended…