Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an urgent security update for its Chrome browser after confirming that two high-severity zero-day vulnerabilities are being actively exploited in the wild. The stable channel has been …

Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salesforce Warns ShinyHunters A critical warning has been issued about an active threat campaign targeting misconfigured Experience Cloud sites. The notorious threat actor group ShinyHunters has claimed responsibility for a …

Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Complete Root Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nine critical vulnerabilities have been discovered in AppArmor, which is a widely used mandatory access control framework for Linux. These vulnerabilities, collectively referred to as “CrackArmor,” enable unprivileged local users …

OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in the GSSAPI Key Exchange patch was applied by numerous Linux distributions on top of their OpenSSH packages. The flaw, tracked as CVE-2026-3497, was uncovered by security …

Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta Launches New Anti-Scam Tools on WhatsApp Facebook and Messenger Meta has launched a suite of advanced anti-scam tools across WhatsApp, Facebook, and Messenger to combat the growing industrialization of …

Attackers Hijack Microsoft 365 Accounts Through OAuth Device Code Abuse Without Stealing Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Analysts at ANY.RUN has identified a sharp spike in phishing campaigns exploiting Microsoft’s OAuth Device Authorization Grant flow, with more than 180 malicious URLs detected within a single week. Unlike …

Critical MediaTek Vulnerability Lets Attackers Steal Android Phone PINs in 45 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the MediaTek Dimensity 7300 chipset allows a physical attacker to extract device PINs, decrypt on-device storage, and steal cryptocurrency wallet seed phrases in approximately 45 seconds, …

Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI assistants have rapidly transformed daily operations, streamlining tasks for teams managing overloaded inboxes, client communications, and incident response. Tools like Microsoft Copilot integrate directly into daily workflows, summarizing emails …

Paloalto Cortex XDR Broker Vulnerability Attackers to Obtain and Modify Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paloalto Cortex XDR Broker Vulnerability A security advisory has been issued for a newly discovered vulnerability affecting the Cortex XDR Broker Virtual Machine (VM). This flaw could allow a highly …

Ericsson US Discloses Data Breach – Hackers Stolen Employees and Customers Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ericsson Data Breach The U.S. subsidiary of a Swedish telecommunications multinational has disclosed a data breach exposing the personal information of employees and customers. The incident did not occur on …