Codex Hacks Samsung TV to Root by Exploiting World-Writable Driver Interfaces

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s Codex AI model successfully escalated privileges to root on a real Samsung Smart TV by exploiting world-writable kernel driver interfaces — a finding that raises serious questions about how hardware vendors handle device security on consumer electronics. The experiment, …

CISA Warns of Fortinet SQL Injection Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Fortinet products. On April 13, 2026, the agency added a severe SQL injection vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This …

Hackers Weaponize Obsidian Shell Commands Plugin to Launch Cross-Platform Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have found a clever way to abuse a trusted productivity tool to deliver malware. By weaponizing Obsidian’s Shell Commands community plugin, attackers are quietly executing malicious code on victims’ machines — all without exploiting a single software vulnerability. …

Hackers Bypass Phishing Emails and Target Okta Identity Systems Instead

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are changing the way they break into organizations. Instead of sending malicious emails and waiting for someone to click a link, attackers are now picking up the phone and calling their way into corporate systems. This shift is one …

Booking.com Confirms Data Breach — Hackers Accessed Customers’ Personal Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Global travel booking giant Booking.com has confirmed a cyberattack in which unauthorized third parties gained access to customers’ personal data, including names, email addresses, phone numbers, and reservation details, raising immediate concerns about downstream phishing attacks targeting millions of travelers …

APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT41 is once again pushing its Linux capabilities forward, this time by quietly turning cloud servers into powerful credential theft platforms. The group’s latest Winnti-family backdoor is a zero‑detection ELF implant designed specifically for Linux workloads running on AWS, Google …

W3LL Phishing Kit Takedown Hits Global Credential Theft and MFA Bypass Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI Atlanta Field Office, working in a historic joint operation with Indonesian law enforcement, has successfully dismantled a massive global phishing network. The investigation targeted the notorious W3LL phishing kit, a sophisticated toolset that enabled cybercriminals to bypass multi-factor …

Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has been silently targeting cryptocurrency users by hiding inside a fake version of Proxifier, a popular proxy software tool. Threat actors set up a GitHub repository designed to look like a legitimate Proxifier download, but the …

Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Rockstar Games has confirmed a data breach after the notorious hacking group ShinyHunters exploited a third-party integration to access the company’s internal Snowflake data warehouse, ultimately leaking over 78.6 million records on April 14, 2026. The breach did not stem …

Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s Claude AI is facing a fresh wave of user-reported disruptions on April 13, 2026, with hundreds of users encountering intermittent HTTP 500 internal server errors across claude.ai, the API, and Claude Code, even as Anthropic’s official status page continues …