Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A new cyberattack campaign has emerged, using cleverly crafted phishing pages and PowerShell tricks to deliver a dangerous piece of malware called SmartRAT. The attack targets Brazilian banking customers and combines social engineering with AI-generated web pages …

Evilginx AiTM Attack Captures Microsoft Credentials, MFA Tokens, and Authenticated Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A growing wave of targeted phishing attacks is putting Microsoft users at serious risk, and the tool behind it is more sophisticated than most people realize. Security researchers have documented how Evilginx, an adversary-in-the-middle framework, is being …

PoC Exploit Released for HTTP/2 Bomb Remote DoS Vulnerability in Apache HTTP Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical Denial of Service vulnerability in Apache HTTP Server, tracked as CVE-2026-49975, dubbed the “HTTP/2 Bomb.” The flaw allows remote attackers to exhaust server memory and disrupt services without authentication, …

Hackers Abuse PowerShell, VBScript, and BAT Files to Deliver Xctdoor Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks is targeting corporate employees through files that look exactly like legitimate job documents. Hackers are distributing malicious LNK files disguised as resumes, and the moment a victim opens one, the infection quietly begins. The attack …

Rust Clipboard Hijacker Uses Fake GitHub Stars and VirusTotal Upvotes to Steal Crypto

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A newly discovered malware campaign is quietly draining cryptocurrency wallets by doing something most security tools never see coming. Instead of relying on brute-force attacks or dark web exploits, the threat actor behind this campaign built a …

Microsoft Office Applications Might Fail to Open Following Windows 11 June Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Microsoft’s June 2026 Patch Tuesday update for Windows 11 (KB5095051) is causing unexpected issues, with users reporting that Microsoft Office applications fail to launch when accessed through certain third-party applications. The issue is listed as a known …

Hackers Actively Exploiting WordPress SMTP Plugin With 100,000+ Installs to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites to harvest configuration data and live email credentials. The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), …

Splunk AI Toolkit Vulnerability Enables Arbitrary OS Command Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Splunk has disclosed a critical security vulnerability in its AI Toolkit that could allow attackers to execute arbitrary operating system commands on affected systems. The flaw, tracked as CVE-2026-20266, has been assigned a CVSS score of 9.1, …

Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed “RoguePlanet,” and confirmed it is actively developing a security patch to address the flaw. Tracked as CVE-2026-50656, the vulnerability was formally published on June …

Google Cloud Vertex AI Allows Attacker to Hijack Victim’s Model and Poison it

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A newly disclosed vulnerability in Google Cloud Vertex AI could have allowed attackers to hijack machine learning model uploads and execute malicious code in victim environments, according to research shared with Google under responsible disclosure. The issue …