New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 11, 2026 A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such …

Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 11, 2026 Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly …

CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 11, 2026 CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal, public GitHub …

Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 11, 2026 A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. …

281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 11, 2026 A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens …

Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 10, 2026 Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a “credible …

One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 10, 2026 Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. …

Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 10, 2026 A critical Citrix flaw is giving intruders a fast route from an internet-facing gateway to a ransomware event. The activity centers on CitrixBleed 2, tracked as CVE-2025-5777, …