AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AmnesiaStealer is a newly identified macOS information stealer that does more than copy saved passwords. It can give criminals quiet control of a browser that is already signed in, turning …

Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mac users are being lured into a ClickFix campaign that turns a routine CAPTCHA check into a path for password theft, remote control, and cryptocurrency mining. It persuades a visitor …

Hugging Face Reportedly Explores $13 Billion Sale Following Recent AI Security Incident

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hugging Face is testing a sale that could value the open-source AI hub at $13 billion or more, even as it is still closing out July’s autonomous-agent intrusion. People familiar …

Hackers Infect Android Car Screens Through Their Built-In Software Update System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target. Rather than tricking drivers into installing a suspicious app, attackers used the software update path …

AWS Network Firewall Now Shows Which Security Rules Are Actually Being Triggered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are matching live network traffic. The new capability is …

Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious npm packages are being used to place a Linux backdoor inside calendar and streak-calculation tools. The packages deliver legitimate date functions, making the malicious code easy to miss. The …

Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in the popular Node.js sandboxing library isolated-vm could allow untrusted JavaScript to escape its V8 sandbox and potentially hijack execution in the host process. The issue, …

Cybermes – AI Red Teaming Agent for Automated Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an enterprise-grade autonomous agent capable of running full penetration tests with …

New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service. Instead, it appears to expose an operator …