Cybersecurity

In-depth analysis, vulnerability reports, and security assessments.

Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records
Cybersecurity
4 min read

Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records

A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. The database was advertised on a cybercrime forum, where the seller

CyberShield TeamRead More
Microsoft 365 Services Outage Impacted Teams, Copilot, Purview and Other Services
Cybersecurity
4 min read

Microsoft 365 Services Outage Impacted Teams, Copilot, Purview and Other Services

A Microsoft 365 outage disrupted access to several widely used enterprise services, including Microsoft Teams, SharePoint Online, OneDrive, Copilot Chat, Microsoft Purview, and Power BI. The incident

CyberShield TeamRead More
Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities
Cybersecurity
4 min read

Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities

Anthropic has released the Claude Security plugin in beta, bringing AI-powered vulnerability scanning directly into Claude Code for developers who want to catch high-severity flaws before they ship. T

CyberShield TeamRead More
Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel
Cybersecurity
5 min read

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a covert channel for receivi

CyberShield TeamRead More
CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
Cybersecurity
4 min read

CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited

CyberShield TeamRead More
Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks
Cybersecurity
3 min read

Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks

A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked as EXIM-S

CyberShield TeamRead More
Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
Cybersecurity
4 min read

Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials

A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application. Security re

CyberShield TeamRead More
Google’s New “Selfie Video” Identity Verification Feature to Gain Access to Locked Accounts
Cybersecurity
4 min read

Google’s New “Selfie Video” Identity Verification Feature to Gain Access to Locked Accounts

Google has introduced a new identity verification feature called “selfie video” designed to help users regain access to locked accounts, marking a significant step in account recovery and authenticati

CyberShield TeamRead More
Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials
Cybersecurity
5 min read

Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

A large-scale cyber campaign is abusing GitHub Actions to turn trusted open source projects into weapons against web hosting servers. Attackers plant malicious workflow files inside compromised reposi

CyberShield TeamRead More
Hackers Abuse Notepad++ Plugins to Compromise Your System Silently
Cybersecurity
3 min read

Hackers Abuse Notepad++ Plugins to Compromise Your System Silently

A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group’s tac

CyberShield TeamRead More
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
Cybersecurity
5 min read

Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware

A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid Ap

CyberShield TeamRead More
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
Cybersecurity
3 min read

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentica

CyberShield TeamRead More
A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool
Cybersecurity
4 min read

A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool

A recently disclosed vulnerability in AWS Kiro, an AI-powered Integrated Development Environment (IDE), reveals how a hidden line of text on a webpage can be exploited for remote code execution on a d

CyberShield TeamRead More
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
Cybersecurity
4 min read

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage n

CyberShield TeamRead More
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
Cybersecurity
3 min read

ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution

ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CV

CyberShield TeamRead More
Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks
Cybersecurity
3 min read

Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks

Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181

CyberShield TeamRead More
Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild
Cybersecurity
3 min read

Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

A critical ServiceNow vulnerability, tracked as CVE-2026-6875, is being actively exploited to allow unauthenticated attackers to escape the script sandbox and execute code on affected systems. The vul

CyberShield TeamRead More
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Cybersecurity
5 min read

Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over

CyberShield TeamRead More
Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts
Cybersecurity
4 min read

Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts

A phishing kit known as Kali365 is targeting U.S. organizations through device code phishing attacks that abuse Microsoft’s legitimate authentication process to hijack Microsoft 365 accounts. Unlike c

CyberShield TeamRead More
OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
Cybersecurity
4 min read

OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers

Hugging Face has disclosed a security incident that security researchers are calling a watershed moment for AI safety: an autonomous AI agent, built on OpenAI models, independently discovered and chai

CyberShield TeamRead More
Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
Cybersecurity
3 min read

Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability

Public proof-of-concept (PoC) exploit code was released for CVE-2026-42980, a local privilege escalation vulnerability in the Windows NT OS Kernel. This vulnerability occurs due to an integer underflo

CyberShield TeamRead More
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
Cybersecurity
5 min read

RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access

A new Linux vulnerability dubbed “RefluXFS” is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected

CyberShield TeamRead More
What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development
Cybersecurity
8 min read

What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development

New research finds that modern AI coding models frequently generate insecure code that exposes AI-generated applications to denial-of-service attacks, hardcoded secrets and authorization failures. The

CyberShield TeamRead More
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
Cybersecurity
4 min read

Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers

A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io

CyberShield TeamRead More
Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities
Cybersecurity
3 min read

Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities

Google has launched Gemini 3.5 Flash Cyber, a specialized cybersecurity model fine-tuned to find, validate, and patch software vulnerabilities faster and more efficiently than mainline Gemini Flash mo

CyberShield TeamRead More
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Cybersecurity
3 min read

Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware

Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arc

CyberShield TeamRead More
Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
Cybersecurity
3 min read

Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

An active malware campaign, dubbed PhantomEnigma, that abuses compromised Brazilian government infrastructure to distribute malicious payloads while evading detection. The operation has hijacked at le

CyberShield TeamRead More
Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
Cybersecurity
5 min read

Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets

Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the t

CyberShield TeamRead More
Now You Can teach a Skill to Claude by Just Recording your Screen
Cybersecurity
3 min read

Now You Can teach a Skill to Claude by Just Recording your Screen

Anthropic has rolled out a new capability in Claude Cowork that lets users teach the AI assistant a repeatable skill simply by recording their screen while performing a task. The feature, called &#822

CyberShield TeamRead More
Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
Cybersecurity
4 min read

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Qilin ransomware has grown from a fast-moving criminal operation into one of the most visible threats in the global extortion landscape. The group encrypts systems and steals data, then pressures vict

CyberShield TeamRead More
This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
Cybersecurity
6 min read

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so secur

CyberShield TeamRead More
Trump’s AI Safety Chief Quits Just Three Months After Taking Charge
Cybersecurity
4 min read

Trump’s AI Safety Chief Quits Just Three Months After Taking Charge

Chris Fall has resigned as the director of the Center for AI Standards and Innovation (CAISI), leaving the Trump administration’s AI safety organization without a permanent leader just three mon

CyberShield TeamRead More
ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands
Cybersecurity
5 min read

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that c

CyberShield TeamRead More
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
Cybersecurity
10 min read

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus webs

CyberShield TeamRead More
GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25
Cybersecurity
4 min read

GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25

GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced

CyberShield TeamRead More
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
Cybersecurity
3 min read

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a

CyberShield TeamRead More
Microsoft to End OneDrive Sync App Updates for Windows 10
Cybersecurity
3 min read

Microsoft to End OneDrive Sync App Updates for Windows 10

Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating leg

CyberShield TeamRead More
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
Cybersecurity
3 min read

Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfa

CyberShield TeamRead More
Where a CBOM solution actually sits: fitting cryptographic inventory into your architecture
Cybersecurity
11 min read

Where a CBOM solution actually sits: fitting cryptographic inventory into your architecture

Most teams meet the idea of a cryptographic bill of materials (CBOM) as a compliance requirement or a post-quantum talking point, and then run straight into a practical question that nobody answered f

CyberShield TeamRead More
Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
Cybersecurity
5 min read

Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon

Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to

CyberShield TeamRead More
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
Cybersecurity
5 min read

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This

CyberShield TeamRead More
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Cybersecurity
3 min read

Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged

CyberShield TeamRead More
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Cybersecurity
4 min read

Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI

Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-base

CyberShield TeamRead More
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
Cybersecurity
4 min read

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from t

CyberShield TeamRead More
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
Cybersecurity
3 min read

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full

CyberShield TeamRead More
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
Cybersecurity
3 min read

EY Data Breach – Hackers Gain Access to IT Support System and Download Documents

Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roug

CyberShield TeamRead More
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
Cybersecurity
5 min read

New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access

A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code exe

CyberShield TeamRead More
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
Cybersecurity
4 min read

OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small

CyberShield TeamRead More
PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools
Cybersecurity
3 min read

PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools

A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing, runs security tools, analy

CyberShield TeamRead More
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
Cybersecurity
4 min read

Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in

CyberShield TeamRead More
F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks
Cybersecurity
3 min read

F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks

F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, warning that unauthenticated attackers could exploit them to trigger memory corruption, crash worker pr

CyberShield TeamRead More
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
Cybersecurity
4 min read

Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution

A critical unpatched vulnerability in Cursor, the popular AI-powered code editor used by over 7 million developers, allows attackers to achieve arbitrary code execution on Windows systems. Simply open

CyberShield TeamRead More
GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches
Cybersecurity
3 min read

GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches

OpenAI’s GPT-5.6 Sol Ultra model independently constructed a complete, working exploit chain for Google Chrome, using nothing but publicly available security patch commits as its starting point.

CyberShield TeamRead More
Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes
Cybersecurity
7 min read

Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes

A Russian-speaking threat actor known as “bandcampro” has weaponized Google’s Gemini CLI AI agent to migrate, deploy, and operate a live command-and-control (C&C) botnet. Remarka

CyberShield TeamRead More
Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS
Cybersecurity
3 min read

Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS

Threat actors are hijacking Anthropic’s Claude AI platform and Google Ads to trick Mac users into infecting themselves with a dangerous new information-stealing malware called MacSync Stealer, a

CyberShield TeamRead More
Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend?
Cybersecurity
5 min read

Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend?

Destiny Stealer activity is rising across Europe and the US, putting corporate accounts, remote access, email data, and sensitive business information at risk. A single infected endpoint can expose pa

CyberShield TeamRead More
Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required
Cybersecurity
4 min read

Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required

Toronto, Canada, July 15th, 2026, CyberNewswire Enterprise-grade binary software verification for one project, one team, or one compliance deadline — without an annual commitment. According to Insigna

CyberShield TeamRead More
Multiple Dell PowerProtect Vulnerabilities Allow Hackers to Gain Full System Access Remotely
Cybersecurity
3 min read

Multiple Dell PowerProtect Vulnerabilities Allow Hackers to Gain Full System Access Remotely

Dell has released security updates to address multiple critical vulnerabilities in its PowerProtect Data Domain products that could allow an unauthenticated remote attacker to gain complete control of

CyberShield TeamRead More
Multiple Windows RDP Vulnerabilities Allow Attackers to Access Sensitive Data
Cybersecurity
4 min read

Multiple Windows RDP Vulnerabilities Allow Attackers to Access Sensitive Data

Microsoft has released security updates to address a series of information disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). These vulnerabilities could allow attackers to read

CyberShield TeamRead More
US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars
Cybersecurity
3 min read

US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars

The Department of Justice has unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two Russia-based “bulletproof hosting” companies. The entities ar

CyberShield TeamRead More
Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets
Cybersecurity
4 min read

Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets

Apple has filed a federal lawsuit against OpenAI, accusing the ChatGPT maker of orchestrating a systematic campaign to steal confidential hardware designs, manufacturing processes, and supplier relati

CyberShield TeamRead More
281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted
Cybersecurity
4 min read

281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted

A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens of these apps transfer

CyberShield TeamRead More
CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak
Cybersecurity
3 min read

CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak

CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal,

CyberShield TeamRead More
Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds
Cybersecurity
4 min read

Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CV

CyberShield TeamRead More
Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts
Cybersecurity
4 min read

Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is

CyberShield TeamRead More
Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens
Cybersecurity
3 min read

Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens

Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older tha

CyberShield TeamRead More
New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents
Cybersecurity
4 min read

New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such

CyberShield TeamRead More
GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes
Cybersecurity
3 min read

GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes

GNU Guix has disclosed four serious security vulnerabilities affecting its package substitution and channel-management features. Three flaws in the guix substitute utility can enable remote privilege

CyberShield TeamRead More
Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour
Cybersecurity
5 min read

Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour

A critical Citrix flaw is giving intruders a fast route from an internet-facing gateway to a ransomware event. The activity centers on CitrixBleed 2, tracked as CVE-2025-5777, which can expose memory

CyberShield TeamRead More
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution
Cybersecurity
9 min read

Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution

A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold. The campaign begins with convincing booking-themed spam and steers victims toward a ZI

CyberShield TeamRead More
One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers
Cybersecurity
3 min read

One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers

Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message.

CyberShield TeamRead More
OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks
Cybersecurity
4 min read

OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks

OpenAI has released the GPT-5.6 model family for general availability, introducing three models aimed at different performance and cost requirements: Sol, the flagship system; Terra, a balanced option

CyberShield TeamRead More
Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat
Cybersecurity
3 min read

Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat

Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a &#

CyberShield TeamRead More
Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks
Cybersecurity
4 min read

Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks

A new security analysis by Binarly Research has uncovered six critical vulnerabilities in the widely used U-Boot bootloader, exposing embedded systems and server management platforms to denial-of-serv

CyberShield TeamRead More
Top 10 Best Unified Threat Management (UTM) Solutions in 2026
Cybersecurity
13 min read

Top 10 Best Unified Threat Management (UTM) Solutions in 2026

If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sop

CyberShield TeamRead More
Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets
Cybersecurity
4 min read

Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets

The Wireshark Foundation has released Wireshark 4.6.7, a security-focused update that fixes multiple vulnerabilities that can cause the popular network protocol analyzer to crash when processing speci

CyberShield TeamRead More
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
Cybersecurity
4 min read

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

A large-scale AWS intrusion reveals how AI-assisted attackers can chain familiar cloud techniques to move from initial access to full environmental compromise in roughly 72 hours, not through novel ex

CyberShield TeamRead More
Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code
Cybersecurity
3 min read

Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code

IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. A thr

CyberShield TeamRead More
ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
Cybersecurity
4 min read

ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites

A large hacking campaign is sweeping across websites worldwide, turning ordinary content management systems into launchpads for attackers. Small and medium sized businesses in Australia and beyond are

CyberShield TeamRead More
Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers
Cybersecurity
4 min read

Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers

AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections ti

CyberShield TeamRead More
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
Cybersecurity
5 min read

GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses

GodDamn ransomware has emerged as a serious threat, marking the third rebrand of a family that has quietly evolved since 2022. What makes this variant stand out is not just its encryption ability but

CyberShield TeamRead More
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybersecurity
5 min read

Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts

Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo

CyberShield TeamRead More
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
Cybersecurity
4 min read

Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers

Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and p

CyberShield TeamRead More
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
Cybersecurity
4 min read

New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claud

CyberShield TeamRead More
Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic
Cybersecurity
3 min read

Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending

CyberShield TeamRead More
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
Cybersecurity
5 min read

RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access

A resurfaced Android banking trojan called RedHook has returned with a dangerous new trick, hijacking a legitimate developer feature to quietly seize deep control of infected phones. Rather than relyi

CyberShield TeamRead More
RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Cybersecurity
3 min read

RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment

Roundcube has released version 1.7 to patch six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that require zero user interaction to exploit. The update addre

CyberShield TeamRead More
APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor
Cybersecurity
5 min read

APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides sh

CyberShield TeamRead More
ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers
Cybersecurity
6 min read

ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers

A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a

CyberShield TeamRead More
DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists
Cybersecurity
3 min read

DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists

DuckDuckGo has rolled out native YouTube ad blocking across its browser applications, automatically stripping pre-roll and mid-roll video ads without requiring users to install third-party extensions.

CyberShield TeamRead More
Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain
Cybersecurity
5 min read

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official In

CyberShield TeamRead More
Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes
Cybersecurity
5 min read

Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes

A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victim

CyberShield TeamRead More
PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution
Cybersecurity
5 min read

PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution

A newly identified strain of Android spyware called PromptSpy has become the first mobile malware known to call on generative AI while it is actually running on a victim’s device. Rather than re

CyberShield TeamRead More
Parrot 7.3 Released With Optimized Packages and Updated Tools
Cybersecurity
3 min read

Parrot 7.3 Released With Optimized Packages and Updated Tools

Parrot Security has released Parrot OS 7.3, introducing significant system-level optimizations, updated security tools, and a redesigned application management experience to improve performance and us

CyberShield TeamRead More
Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories
Cybersecurity
8 min read

Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories

This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux releas

CyberShield TeamRead More
Flipper Zero Firmware Development Continues With New Community Contribution Rules
Cybersecurity
3 min read

Flipper Zero Firmware Development Continues With New Community Contribution Rules

Flipper Devices has responded to intense community backlash over perceptions that it had abandoned active development of the Flipper Zero firmware. In a statement addressing the controversy, the compa

CyberShield TeamRead More
Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2
Cybersecurity
3 min read

Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2

Microsoft has rolled out KB5095189, a new cumulative update targeting the Out-of-Box Experience (OOBE) for Windows 11, versions 24H2 and 25H2. Released on June 23, 2026, this update refines the initia

CyberShield TeamRead More
T3MP3ST Security Framework With 35 Tools, Turns AI Coding Agents Into 0-Day Bug Hunters
Cybersecurity
3 min read

T3MP3ST Security Framework With 35 Tools, Turns AI Coding Agents Into 0-Day Bug Hunters

A newly released open-source security framework called T3MP3ST is turning general-purpose AI coding agents like Claude Code, OpenAI’s Codex, and Hermes into autonomous red-teaming operators with

CyberShield TeamRead More