Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new macOS malware that was undocumented previously, is quietly tricking users through fake Cloudflare human verification pages. Called Infiniti Stealer, this threat uses a well-known social engineering trick called ClickFix to convince Mac users into running dangerous commands directly …

New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly analyzed local privilege escalation vulnerability in the Windows Error Reporting (WER) service allows attackers to easily gain full SYSTEM access. The flaw, tracked as CVE-2026-20817, was considered so structurally dangerous that Microsoft completely removed the vulnerable feature rather …

ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) has released a critical security advisory warning network administrators of a high-severity vulnerability affecting the Kea DHCP server. Tracked as CVE-2026-3608, this flaw allows unauthenticated remote attackers to trigger a stack overflow error. When successfully …

Anthropic’s Leaked Drafts Expose Powerful New AI Model “Claude Mythos”

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has inadvertently exposed highly sensitive internal documents, revealing the existence of a powerful, unreleased AI model dubbed “Claude Mythos.” The leak, which stems from an unsecured and publicly searchable data cache, has raised immediate alarms within the cybersecurity community, …

Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability in Anthropic’s Claude Chrome Extension exposed over 3 million users to silent prompt-injection attacks, allowing malicious websites to hijack the AI assistant without user interaction. The flaw, now patched, could have enabled attackers to steal Gmail …

Critical NVIDIA Vulnerabilities Enables RCE and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical March 2026 security updates have been released to fix multiple vulnerabilities across enterprise and AI software systems. The latest advisories highlight severe flaws that could enable attackers to execute arbitrary code, trigger denial-of-service (DoS) conditions, or escalate privileges within compromised …

New ClickFix Attack Leverage Windows Run Dialog Box and macOS Terminal to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A social engineering technique called ClickFix has resurfaced with significant force, tricking users on both Windows and macOS into manually executing malicious commands that quietly install malware on their devices. First documented in late 2023, the method has rapidly grown …

Leak Bazaar Turns Stolen Corporate Data Into a Structured Criminal Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “Snow” from SnowTeam posted an advertisement on the Russian-speaking TierOne (T1) cybercrime forum on March 25, 2026, introducing a new criminal service called Leak Bazaar. The platform is not a traditional data leak site. Instead, …

VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and technically advanced rootkit called VoidLink has emerged as a serious threat to Linux systems, blending Loadable Kernel Modules (LKMs) with extended Berkeley Packet Filter (eBPF) programs to hide deep inside the operating system’s core. First documented by …

CISA Warns of Langflow Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the Langflow platform to its Known Exploited Vulnerabilities (KEV) catalog on March 25, 2026. The vulnerability, tracked as CVE-2026-33017, involves a highly dangerous code injection …