CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, United States, March 19th, 2026, CyberNewswire Cybersecurity has entered a new phase, one defined less by reactive controls and more by continuous, intelligence-driven operations. As attack surfaces expand and adversaries increasingly leverage AI, the modern CISO is tasked with …

Critical Ubiquiti UniFi Vulnerabilities Allow Attackers to Seize Full Control of Underlying Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ubiquiti UniFi Vulnerabilities Ubiquiti has disclosed two critical-to-high severity vulnerabilities in its widely deployed UniFi Network Application, including a maximum-severity flaw that could allow unauthenticated attackers to seize full control of underlying systems. Organizations running affected versions are urged to …

‘Vibe-Coded’ Malware Campaign Uses Fake Tools, CDNs and File Hosts to Infect Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The rise of AI-assisted coding has brought real value to developers around the world, but it has also opened a new door for cybercriminals to exploit. A concept known as “vibe coding” — where users simply describe what they want …

Malicious ‘Pyronut’ Package Backdoors Telegram Bots With Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Python package named pyronut has been discovered on the Python Package Index (PyPI), targeting developers who build Telegram bots by impersonating the popular pyrogram framework. Rather than relying on typosquatting — where a name resembles a legitimate one — the threat actor …

Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Vulnerabilities Exfiltrate Sensitive Data Redirect Malicious Websites Three chained vulnerabilities in Claude.ai, Anthropic’s widely used AI assistant, that together allow attackers to silently exfiltrate sensitive conversation data and redirect unsuspecting users to malicious websites, all without requiring any integrations, …

Backdoored Open VSX Extension Used GitHub Downloader to Deploy RAT and Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular code editor extension listed on the Open VSX registry was discovered carrying hidden malware that silently fetches and runs a remote access trojan (RAT) and a full infostealer directly onto developer machines without any visible warning sign. The …

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor with ties to Iran has had their entire working infrastructure exposed after carelessly leaving an open directory on their own staging server, handing researchers a rare look into a live botnet operation. The leak revealed a 15-node …

WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines.​ WaterPlum has been running …

CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Microsoft SharePoint Vulnerability Exploit A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to the Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that …

New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. First spotted in December 2025, this command-and-control (C2) framework …