Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Vulnerabilities Exfiltrate Sensitive Data Redirect Malicious Websites Three chained vulnerabilities in Claude.ai, Anthropic’s widely used AI assistant, that together allow attackers to silently exfiltrate sensitive conversation data and redirect …

Backdoored Open VSX Extension Used GitHub Downloader to Deploy RAT and Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular code editor extension listed on the Open VSX registry was discovered carrying hidden malware that silently fetches and runs a remote access trojan (RAT) and a full infostealer …

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor with ties to Iran has had their entire working infrastructure exposed after carelessly leaving an open directory on their own staging server, handing researchers a rare look …

WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development …

CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Microsoft SharePoint Vulnerability Exploit A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to …

New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ …

Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. Cisco disclosed the flaw on March 4, …

New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DarkSword iOS Exploit A sophisticated full-chain iOS exploit kit dubbed DarkSword, actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 to steal sensitive personal …

OpenAI Launches GPT-5.4 Mini and Nano to Provide Answers 2X Faster

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI Launches GPT-5.4 Mini and Nano OpenAI has officially launched GPT-5.4 mini and GPT-5.4 nano, releasing its most capable small models designed to handle high-volume, latency-sensitive workloads. The new mini …