Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 23, 2026 A critical vulnerability has been disclosed in FFmpeg’s MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in some scenarios, achieve remote code execution …

Hackers Using FortigateSniffer Tool That Turns Compromised Firewalls Into Password Collectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 23, 2026 A financially motivated threat actor has deployed a custom Golang-based tool called FortigateSniffer across more than 430,000 FortiGate firewalls globally, silently harvesting over 110 million credentials since …

OpenAI Releases GPT‑5.5‑Cyber With Full Automation for Vulnerability Detection and Patching

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 23, 2026 OpenAI has officially launched the full version of GPT‑5.5‑Cyber, a specialized AI model engineered for advanced vulnerability detection, patch generation, and automated remediation at machine speed. The …

Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package …

Microsoft Entra Conditional Access Policies Can Be Bypassed Via Nested App Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft Entra Conditional Access Policies (CAPs), a core security control for Azure and Microsoft 365 tenants, were recently found vulnerable to a bypass technique involving Nested App …

AI-Powered iOS Apps Leaking LLM API Credentials Through Network Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered iOS applications are increasingly leaking large language model (LLM) API credentials through network traffic, exposing developers to large-scale abuse of their LLM accounts and cloud resources. A recent empirical …

Hackers Use RemotePC RMM and PowerShell Stagers to Deploy Prinz Eugen Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly identified ransomware group is using remote management software and scripted attack tools to compromise organizations and deploy a sophisticated encryption threat called Prinz Eugen. The …

Microsoft’s New Option Allows Organizations to Block Copilot Access to Office Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft has announced a significant update to its Microsoft 365 security and compliance features, introducing enhanced controls that allow organizations to block Copilot and other connected experiences …