A Leaked Android RAT Is Powering 170 Servers and Its Successor Is Already Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A leaked Android remote access trojan called Flying Eagle is being used across a large and growing criminal network. The toolkit lets operators create fake Android apps, …

20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of publicly exposed data center servers in just …

WhatsApp Adds End-to-End Encryption for Voice and Video Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 WhatsApp has introduced a new set of calling features alongside expanded end-to-end encryption for voice and video communications, emphasizing its commitment to secure, cross-platform communication. This update …

Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the flaw affects Security Management Server and …

JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI systems found and chained previously …

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a …

Critical Gitea Vulnerability Allows Attackers to Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A critical vulnerability in Gitea, identified as CVE-2026-60004, could enable attackers to execute arbitrary shell commands on vulnerable servers. This issue affects Gitea versions 1.17 through 1.27.0 …

Bank of Baroda Data Breach – Hackers Gained Access Via Employee Email Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 Bank of Baroda has confirmed a cybersecurity incident in which attackers gained unauthorized access to an employee’s email account, exposing internal communications and potentially sensitive information, raising …

Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 A cluster of malicious npm packages has been used to deliver a cross-platform remote access trojan against developers who use Alibaba-related tools. The campaign hides its harmful …

Hackers Are Hiding Commands in Emails to Trick the AI Systems Protecting You

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 29, 2026 Attackers are beginning to hide malicious instructions inside ordinary emails, documents, calendar invites, and online advertisements. The goal is not always to fool a person. Instead, the …