Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or Configuration Manager. The flaws could allow an attacker …

Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery …

HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders. It gives intruders tools designed to …

GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function. The issue can allow attackers to manipulate database queries via …

New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content. Trellix …

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to install malware …

Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that reaches internet-facing edge …

ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 17, 2026 ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took …