150+ npm Packages Promises Wi-Fi Bypass Students Using Their Systems for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Nearly 150 npm packages posing as school Wi-Fi bypass tools were used to turn visiting browsers into potential DDoS engines. The campaign presented itself as harmless tutoring-branded …

Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is retiring phishable SMS and voice-based multifactor authentication in Microsoft Entra ID, replacing them with passkeys as the default sign-in method starting September 1, 2026. The move responds to …

US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has imposed sanctions on First VPN Service (1VPNS), a VPN provider accused of supplying infrastructure …

Critical ServiceNow Vulnerability Allows Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ServiceNow has disclosed and fixed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to execute code within affected ServiceNow environments. The flaw, tracked as CVE-2026-6875, …

Chrome Extension Used by 1.6 Million Users Silently Included Data Exfiltration Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, …

New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 CrashStealer, a native C++ macOS infostealer that disguises itself as Apple’s built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before …

Torq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Torrance, California, USA, July 13th, 2026, CyberNewswire Criminal IP, the cyber threat intelligence search engine and attack surface management platform, today announced a new partnership and integration …

Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Turla, a long-running cyber espionage operation linked by French authorities to Russia’s Federal Security Service, has again drawn attention after investigators detailed compromises affecting French organizations. The …

Internet-Wide Scans Target MCP Servers, Claude Credentials, and Exposed AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Internet-facing AI systems are becoming a new target for opportunistic attackers. Recent scanning activity shows that threat actors are actively searching for Model Context Protocol, or MCP, …