1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in OpenClaw, the open-source AI personal assistant trusted by over 100,000 developers, has been discovered and weaponized into a devastating one-click remote code execution exploit. Security researchers …

State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The …

Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of …

Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its …

AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional …

SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control …

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The …

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active …

TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part …