Critical Dgraph Database Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A maximum-severity vulnerability in Dgraph, a popular open-source graph database. Tracked as CVE-2026-34976, this critical flaw carries a perfect CVSS score of 10.0. It allows unauthenticated remote attackers to bypass all security controls, overwrite entire databases, read sensitive server files, …

Hackers Use Poisoned Axios Package and Phantom Dependency to Spread Cross-Platform Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

One of the most widely used JavaScript libraries in the world was turned into a weapon on March 30, 2026, when attackers poisoned the Axios npm package and silently deployed malware on developer machines running Windows, macOS, and Linux. With …

Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique, exposing hundreds of thousands of developers to credential theft and supply chain compromise. According …

Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate users into downloading malicious payloads by mimicking the widely used communication platform. As …

New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Remote Access Trojan (RAT) called ResokerRAT has been found targeting Windows systems by abusing Telegram’s widely used Bot API to receive commands and send stolen data back to attackers. Unlike traditional malware that relies on custom command-and-control servers, …

METATRON – Open-Source AI Penetration Testing Assistant Brings Local LLM Analysis to Linux

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source penetration testing framework called METATRON is gaining attention in the security research community for its fully offline, AI-driven approach to vulnerability assessment. Built for Parrot OS and other Debian-based Linux distributions, METATRON combines automated reconnaissance tooling with …

36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed …

CISA Adds TrueConf Vulnerability to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting TrueConf software to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-3502, this security flaw is currently facing active exploitation in the wild. The discovery has …

2,000+ FortiClient EMS Instances Exposed Online Amid Active RCE Vulnerability Exploits in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has issued an urgent warning to FortiClient Enterprise Management Server (EMS) administrators after identifying over 2,000 publicly accessible instances globally, two of which are now confirmed to be actively exploited through critical unauthenticated remote code execution (RCE) …

Google DeepMind Researchers Warn Hackers Can Hijack AI Agents Through Malicious Web Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Google DeepMind have published a comprehensive study revealing that autonomous AI agents browsing the web are deeply vulnerable to a new class of attacks called “AI Agent Traps,” which are adversarial content engineered into websites and digital resources …