Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed …

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote …

OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public bulletin board, according to research published at collusion.wiki. …

Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an unauthenticated message pass a Direct …

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted …

Microsoft Teams to Add QR Code Protection in Teams Messaging

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users. The feature, currently listed as “In Development” …

14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing remote-access trojan. The files were distributed as macOS disk …

Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large campaign has compromised more than 14,000 internet-connected Dahua cameras, exposing how vulnerable surveillance equipment can become a gateway to video feeds and device settings. The operation ran for …

Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and …

OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled GPT-6 Astra, a frontier AI model the company says can identify zero-day vulnerabilities and create working proof-of-concept exploits during authorized cybersecurity tests. Announced on September 3, 2026, …