Mozilla Unveils Kill Switch to Disable All Firefox AI features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Firefox 148 introduces comprehensive AI controls, giving users greater control over artificial intelligence features built into the browser. The new security-focused setting provides a centralized toggle to block current and future generative AI functionalities. Addressing growing privacy and security concerns …

Beware of Malicious Party Invitations that Tricks Users into Installing Remote Access Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is tricking people with fake party invitations that secretly install remote access software on Windows computers. The attack uses social engineering to deliver ScreenConnect, a legitimate remote support tool, allowing threat actors to gain complete control …

Apache Syncope Vulnerability Let Attackers Hijack User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical XML External Entity (XXE) vulnerability has been disclosed in the Syncope identity management console. The flaw could allow administrators to expose sensitive user data and compromise session security inadvertently. The vulnerability, tracked as CVE-2026-23795, affects multiple versions of …

APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT28, the Russia-linked advanced persistent threat group, has launched a sophisticated campaign targeting Central and Eastern Europe using a zero-day vulnerability in Microsoft Office. The threat actors leveraged specially crafted Microsoft Rich Text Format (RTF) files to exploit the vulnerability …

Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users …

Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models. The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, potentially allowing attackers with valid credentials to execute arbitrary commands …

OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem. OpenClaw, previously known as Clawdbot and briefly …

Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated espionage campaign attributed to the Chinese Advanced Persistent Threat (APT) group Lotus Blossom (also known as Billbug). The threat actors compromised the infrastructure hosting the popular text editor Notepad++ to deliver a custom, previously undocumented backdoor named “Chrysalis”. …

DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy …

30 Wind and Solar Farms in Poland Faced Coordinated Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On December 29, 2025, Poland faced a coordinated assault targeting more than 30 wind and solar farms, alongside a large combined heat and power plant and a manufacturing facility. The attacks occurred during severe winter weather, when temperatures dropped and …