VaultJacking Attack Steals Entire Google Password Manager Vault With One Captured PIN

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing technique called VaultJacking has emerged, and it is raising serious alarms across the cybersecurity community. With just a single captured 6-digit PIN, an attacker can walk away …

AI-Generated npm Malware Accidentally Exposes Threat Actor’s Private GitHub Token

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 A new wave of AI-generated malware is hitting the open-source software ecosystem, and this time, the attacker made a critical mistake that gave researchers a rare inside …

Claude Opus 4.8 Released With Ability to Work as an Experienced Engineer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 Anthropic has launched Claude Opus 4.8, the latest iteration of its flagship AI model, bringing sharper judgment, improved self-awareness about its own progress, and significantly extended autonomous …

Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability has been discovered in OpenVPN Connect for macOS, enabling local attackers to execute arbitrary commands with elevated privileges through the application’s background service component. Tracked …

Hackers Deploy VIP Keylogger Through Phishing Emails Masquerading as Business Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 Hackers are using deceptive phishing emails dressed up as routine business documents to spread a dangerous malware strain known as VIP Keylogger. The campaign has been active …

ClearFake Uses BSC Testnet Smart Contracts for Takedown-Resistant Command and Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerously clever malware campaign called ClearFake has been caught using blockchain smart contracts to run its operations, making it nearly impossible for security teams to shut it …

New Linux CIFSwitch Kernel Vulnerability Allows Attackers to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed “CIFSwitch” enables low-privileged users to gain root access by abusing a logic flaw between the Linux kernel …

Carnival Cruise Data Breach Exposes Millions of Customers’ Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 Carnival Corporation, the world’s largest cruise company and parent of Carnival Cruise Line, has begun notifying customers of a significant cybersecurity breach that exposed sensitive personal data …

Hackers Use GHOSTYNETWORKS and OMEGATECH to Host JS Malware Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 In March 2026, a wave of malicious spam emails began hitting inboxes across multiple countries and industries. Threat actors were quietly distributing a JavaScript-coded backdoor, targeting organizations …

Gitea Container Vulnerability Exposes Private Container Images to Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 28, 2026 A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self-hosted Git and …