Hackers Abuse Legitimate Meta Business Manager Notifications to Deliver Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is actively targeting businesses worldwide by exploiting one of the most trusted tools in digital marketing — Meta’s Business Manager platform. Cybercriminals have found a clever way to send deceptive emails that look exactly like genuine …

Microsoft 365 Network-Level Disruption Affecting Exchange Online, Teams, and Core Suite Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A network-level disruption struck multiple Microsoft 365 services on Wednesday evening, knocking out or degrading access to Exchange Online, Microsoft Teams, and the broader Microsoft 365 suite for users across affected regions. The incident, tracked under issue ID MO1274150, began …

Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilTokens and AMOS redefine modern phishing attacks Two significant threat campaigns from March 2026, one abusing Microsoft’s OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS infostealer against macOS users who work with AI development tools …

IBM Identity and Verify Access Vulnerabilities Allow Remote Attacker to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security bulletin highlights multiple vulnerabilities in Verify Identity Access and Security Verify Access products. If left unpatched, these widespread security flaws could allow malicious actors to access sensitive information, escalate their system privileges, or cause a complete denial-of-service …

Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly sophisticated, unpatched zero-day exploit is actively targeting users of Adobe Reader. Detected by the EXPMON threat-hunting system, this malicious PDF file is designed to steal sensitive local data and perform advanced system fingerprinting. The exploit functions flawlessly on …

Anthropic Unveils Claude Mythos Preview With Powerful Zero-Day Detection Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has introduced Claude Mythos Preview, an advanced language model with extraordinary capabilities for discovering and autonomously exploiting undiscovered zero-day vulnerabilities. To ensure these powerful tools are used defensively, the company has launched Project Glasswing to collaborate with industry partners and …

Microsoft Confirms Recent Windows 11 Update Breaks Start Menu Function

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has acknowledged a server-side issue that disrupted Start Menu search functionality for a subset of Windows 11 23H2 users, and has since deployed a fix to address the problem without requiring users to install any additional updates. The issue, …

Google Expands Chrome Lazy Loading to Video and Audio in New Browser Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google is bringing a major performance enhancement to its browser by expanding native lazy loading capabilities to include video and audio elements. By adding the loading=”lazy” attribute directly to <video> and <audio> HTML tags now allow developers to defer the download of heavy media resources until …

Amazon S3 Files, Turns S3 Buckets as File System to Access Your Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS) has introduced a major update to its cloud storage infrastructure with the launch of Amazon S3 Files. This new feature allows organizations to access their Amazon S3 buckets directly as fully functional shared file systems, eliminating …

Docker Vulnerability Let Attackers Bypass Authorization and Gain Host Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered high-severity vulnerability in Docker Engine could allow attackers to bypass authorization plugins and potentially gain unauthorized access to the underlying host system. Tracked as CVE-2026-34040, this security flaw stems from an incomplete patch for a previously known …