Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple is reportedly developing a software fix for a frustrating iOS 26 bug that has left some users entirely locked out of their iPhones for months. According to a recent report by The Register, Cupertino’s software engineers are scrambling to …

Researcher Uses Claude Opus to Build a Working Chrome Exploit Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amidst the heated debate surrounding Anthropic’s recent announcement of its Mythos and Project Glasswing models, a security researcher has demonstrated the tangible cybersecurity implications of frontier AI. Moving beyond theoretical warnings, the researcher successfully utilized Claude Opus to construct a …

Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal …

Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet’s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability …

Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers …

PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login …

Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, …

Email-Borne Worm Surge Drives New Threat Wave Across Industrial Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A global wave of email-borne worms hit industrial control systems (ICS) in the fourth quarter of 2025, marking one of the most concerning threat shifts seen across operational technology (OT) environments in recent years. The surge was largely tied to …

Fake Zoom SDK Update Delivers Sapphire Sleet Malware in New macOS Intrusion Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean threat actor known as Sapphire Sleet has launched a new campaign against macOS users, using a fake Zoom SDK update to trick victims into running malicious files that steal passwords, cryptocurrency assets, and personal data. Unlike attacks …

Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the marimo Python notebook platform is now being actively used by attackers to deploy a blockchain-powered backdoor on developer systems. The flaw, tracked as CVE-2026-39987, allows remote code execution without authentication, making it a dangerous entry …