Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ExifTool Flaw Malicious Images Trigger Code Execution on macOS A newly discovered vulnerability is challenging the long-held belief that macOS systems are inherently immune to malware. Security researchers from Kaspersky’s Global Research and Analysis Team (GReAT) have identified a critical …

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hikvision Multiple Products Vulnerability A severe vulnerability affecting multiple Hikvision products was added to the Known Exploited Vulnerabilities (KEV) catalog on March 5, 2026. Tracked globally under CVE-2017-7921, this security flaw poses a significant risk to organizations that rely on …

Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A wave of counterfeit AI-powered browser extensions has silently breached over 20,000 enterprise environments, compromising the chat histories of employees who routinely used AI tools for work. These malicious Chromium-based extensions disguised themselves as legitimate AI assistant tools and accumulated …

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns macOS and iOS Vulnerabilities Exploit The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding multiple Apple vulnerabilities currently facing active exploitation. On March 5, 2026, CISA added three security flaws affecting macOS, iOS, iPadOS, …

WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source edge AI system called π RuView is turning ordinary WiFi infrastructure into a through-wall human-sensing platform detecting body pose, vital signs, and movement patterns without a single camera, raising urgent security and surveillance concerns. Researchers and developers …

Hackers Allegedly Selling Exploit for Windows Remote Desktop Services 0-Day Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor is allegedly selling a zero-day exploit for a Windows Remote Desktop Services privilege escalation vulnerability, tracked as CVE-2026-21533, for a staggering $220,000 on a dark web forum. This highly priced exploit targets improper privilege management to grant …

Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zero-Click Command Injection AVideo Platform Allows Stream Hijacking A critical vulnerability in AVideo, a widely used open-source video hosting and streaming platform. Tracked as CVE-2026-29058, this zero-click flaw carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating …

Cognizant TriZetto Data Breach Exposes Health Information of 3.4 Million Patients

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cognizant TriZetto Data Breach TriZetto Provider Solutions, a healthcare technology subsidiary of the IT services giant Cognizant, has officially disclosed a massive cybersecurity data breach affecting the sensitive health information of 3,433,965 patients. The healthcare organization recently filed a formal …

Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious imToken Chrome Extension Socket’s Threat Research Team has discovered a malicious Google Chrome extension named “lmΤoken Chromophore” that actively steals cryptocurrency wallet credentials. Masquerading as a harmless hex color visualizer, the extension actually impersonates the popular non-custodial wallet brand …

OpenAI Launches Codex Security that Discover, Validate and Patch Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI Launches Codex Security OpenAI has announced the launch of Codex Security, an application security agent engineered to autonomously identify, validate, and remediate complex vulnerabilities within enterprise and open-source codebases. Formerly known as Aardvark, the tool leverages frontier AI models …