Hackers Can Weaponize ‘Summarize with AI’ Buttons to Inject Memory Prompts Into AI Recommendations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security threat has emerged targeting users of AI assistants through a technique called AI Recommendation Poisoning. Companies and threat actors embed hidden instructions in seemingly harmless “Summarize with AI” buttons found on websites and emails. When clicked, these …

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign targeting macOS users has emerged, deploying a dangerous stealer malware through an evolved version of the ClickFix attack technique. Named “Matryoshka” after the Russian nesting dolls, this variant uses nested obfuscation layers to hide malicious …

LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new version of LockBit ransomware has emerged, targeting multiple operating systems and threatening businesses worldwide. LockBit 5.0, released in September 2025, represents a major upgrade to one of the most active ransomware families in recent years. This version …

New ZeroDayRAT Attacking Android and iOS For Real-Time Surveillance and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ZeroDayRAT is a new mobile spyware platform sold openly through Telegram, with activity first observed on February 2, 2026. It targets Android (5–16) and iOS (up to 26), giving attackers one cross-platform tool. From a browser-based control panel, an operator …

Critical Airleader Vulnerability Exposes Systems to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Airleader Vulnerability A newly disclosed vulnerability in an industrial control system (ICS) monitoring solution has raised concerns across multiple critical infrastructure sectors. Published by CISA under advisory code ICSA-26-043-10, the flaw has been assigned CVE-2026-1358 and carries a CVSS v3 score of 9.8, …

OpenClaw Founder Peter Steinberger Officially Joins OpenAI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw Founder Peter Steinberger Joins OpenAI OpenClaw founder Peter Steinberger has officially joined OpenAI, marking a notable collaboration between open-source innovation and one of the world’s leading AI research organizations. According to Steinberger’s announcement titled “OpenClaw, OpenAI and the Future,” his new role focuses …

Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The state-sponsored threat group Lotus Blossom successfully breached the official hosting infrastructure of Notepad++ between June and December 2025, targeting users across government agencies, telecommunications companies and critical infrastructure sectors. The attackers gained access by compromising the shared hosting provider’s …

CISA Warns of ZLAN ICS Devices Vulnerabilities Allows Complete Device Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ZLAN ICS Devices Vulnerabilities An alert regarding two critical vulnerabilities found in ZLAN Information Technology Co.’s ZLAN5143D industrial communication device. According to the advisory (ICSA-26-041-02), successful exploitation could allow attackers to gain complete control of affected systems by bypassing authentication …

Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BeyondTrust Vulnerability Exploit A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered …

Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome 0-Day Vulnerability Exploited Google has urgently patched a high-severity zero-day vulnerability in Chrome, confirming active exploitation in the wild. Tracked as CVE-2026-2441, the flaw is a use-after-free bug in the browser’s CSS handling, reported by independent researcher Shaheen Fazim …