Security researchers at Wiz scanned 3,074 internet-facing deployments of LiteLLM in February and found something that should embarrass more than a few…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud…
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains
A newly published investigation has uncovered what may be the largest documented fake-shop network to date, spanning roughly 119,000 domains and dubbed…
One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android
A new wave of WeChat vulnerability can turn an incoming voice call into a zero-click account takeover, enabling a compromised account to target another…
LG Targets Residential Proxies in New Smart TV Security Move
Several webOS apps using residential proxy technology are being suspended by LG Electronics for routing third-party traffic through smart TVs. The company…
Ransomware Affiliate Pretends to be Recovery Service for Extortion
An alleged ransomware affiliate is pretending to be a ransomware recovery service named “Ransom Busters,” reaching out to victims before the attacks…
Critical FreeIPA Bug Can Let Attackers Take Over Admin Rights
FreeIPA users and Red Hat Identity Management administrators should treat CVE-2026-76578 as a critical authentication-bypass flaw that can lead to full…
Critical Cisco Firewall Management Flaw Exploited in Attacks
Cisco has alerted customers regarding a critical authentication bypass flaw inside the Secure Firewall Management Center (FMC) software that is being…
India Orders Google to Remove 57 Firebase Sites Linked to Cyber Scams
The Indian government has directed Google to take down dozens of websites and databases hosted on Firebase after finding that cybercriminals were…
Hackers Turn ScreenConnect Into Its Own Infection Vector in New Worm-Like Campaign
A remote access tool built for IT departments and help desks is now being weaponized against them. Researchers at Huntress say they’ve found hacked…
Liquid Network Attacker Returns 85% of Stolen Bitcoin After Blockstream Patches Bug
The attacker who stole 4,000 bitcoin (BTC) from Liquid Network’s federation wallet on the weekend has returned 85% of the funds after Blockstream…
PEEP Turns Chrome and Edge Into Hidden Backdoors
Cybersecurity researchers have uncovered PEEP, a Chromium-based post-exploitation toolkit that turns Chrome and Edge into stealthy backdoors after an…
Attackers Exploit TeamCity Flaw to Breach JetBrains Cadence
JetBrains has revealed a security incident involving its Cadence cloud development service after attackers gained access through an unpatched TeamCity…
REVSTEALER Malware Disables Windows Security to Run a Crypto Miner
A new malware campaign associated with the REVSTEALER information stealing malware has been discovered using another four additional malicious programs to…
Turner Discloses Data Breach Exposing Salary Info, Bank Accounts, and SSNs
Turner Construction has notified at least 6,098 people of a data breach that uncovered social security numbers, salaries, dates of birth and bank account…
Google Just Patched a Chrome Security Flaw That Hackers Were Already Exploiting
Before getting into the specifics, it helps to understand what makes this kind of vulnerability different from a regular software bug. A “zero-day” is a…
F5 BIG-IP APM Malware Installs a PHP Web Shell Into Memory, Escaping Disk Scans
Sophos X-Ops has found an advanced Linux rootkit that can conceal a PHP web shell completely in server memory, which makes it harder for traditional…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
StyleSmuggler Flaw Allows Attackers to Exploit Zero Day With Remote Code Execution
Threat actors are exploiting a newly found zero-day flaw in Magento Open Source and Adobe Commerce to install persistent backdoors and compromise online…
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains
A newly published investigation has uncovered what may be the largest documented fake-shop network to date, spanning roughly 119,000 domains and dubbed…
