AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a lost device, then uses convincing recovery messages to capture …

WatchGuard Agent for Windows Vulnerability Allows Code Execution with Elevated Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code with elevated privileges. The flaws, tracked as CVE-2026-57910 and CVE-2026-57909, …

Adobe Campaign Classic Vulnerabilities Enable Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has released a Priority 1 security update for Adobe Campaign Classic following the identification of three critical vulnerabilities that could allow unauthenticated remote attackers to execute arbitrary code. The …

Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container, with fixes rolled into version 11.0.25. The flaws, disclosed on …

CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency has added a newly disclosed Gitea vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw, tracked as CVE-2026-60004, …

21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access could chain the flaws to bypass authentication, inject commands, and …

Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked as CVE-2026-75604, affects Next.js applications …

OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has removed a cluster of ChatGPT accounts linked to a covert influence operation from Russia. The accounts produced social-media posts and replies designed to steer people toward the International …

Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied to Tortoiseshell, also tracked as Mirage Kitten, UNC1549 and Nimbus …

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware. The campaign turns a familiar AI software search into a …