Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream. The …

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers. The pages claim to inspect a device, report serious …

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AliExpress’s homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears to power an aggressive device-fingerprinting system while producing an unexpected real-world side effect: interfering with …

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over accounts by knowing only a registered mobile …

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware. …

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in Windows Presentation Foundation (WPF) applications, creating fresh headaches for enterprises …

Multiple Zscaler Client Connector Vulnerabilities Enable RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities affecting Zscaler Client Connector have been disclosed, potentially allowing remote code execution on vulnerable systems. Tracked as CVE-2026-59568, the critical flaw chain enables an unauthenticated and unprivileged attacker …

91 Spring Vulnerabilities Impact 209,000+ Software Components Across Open-Source Ecosystem

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcom has released a major batch of Spring security advisories, with Sonatype tracking 91 CVEs across Spring Framework and related projects. The August 20, 2026 disclosure affects an estimated 209,569 …

EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, …