GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign called “GitBait” has been caught targeting Mexico’s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that …

Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Threat actors are increasingly targeting cloud logging services to evade detection and maintain persistent visibility into compromised environments, according to recent research by Palo Alto Networks Unit 42. These services, designed as a critical security layer, are …

Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A dangerous new cyber campaign is putting macOS users at serious risk, and it does not rely on software bugs to do its damage. Instead, the attackers trick people into handing over their own passwords and sensitive …

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 London, United Kingdom, June 17th, 2026, CyberNewswire New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under control, against 7% of the practitioners running it day-to-day. Across 1,000 IT professionals in …

FortiBleed – 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 An exhaustive cyber espionage campaign now dubbed “FortiBleed” has silently compromised over 73,932 unique Fortinet firewall URLs across 194 countries. Originally uncovered by security researcher Volodymyr “Bob” Diachenko and subsequently analyzed by Hudson Rock, this dataset reveals a highly automated, …

FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known Chinese cyberespionage group has taken a major step forward in its hacking capabilities. The threat actor, tracked as FishMonger, has brought its SprySOCKS backdoor to Windows for the first time, after years of deploying it exclusively on Linux. …

ErrTraffic MaaS Uses Fake reCAPTCHA and Cloudflare Turnstile Lures to Execute PowerShell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A new and rapidly growing cybercrime tool called ErrTraffic is making waves across the threat landscape, targeting internet users through cleverly disguised verification screens. The framework tricks victims into running malicious PowerShell commands on their own machines, …

Multiple JetBrains IDE Plugins 70,000+ Installs Caught Stealing AI keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A large-scale malware campaign has been uncovered on the JetBrains Marketplace, where at least 15 malicious IDE plugins were found stealing sensitive API keys from developers. These plugins, downloaded over 70,000 times, were published under seven different …

CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 CISA has added a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaw affects Oracle PeopleSoft Enterprise PeopleTools and enables unauthenticated attackers to gain …

Fortra Access Manager Vulnerability Enables Remote Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Fortra has disclosed a critical security vulnerability in its Core Privileged Access Manager (BoKS) that could allow remote attackers to execute arbitrary commands on affected systems. CVE-2026-9862 is a critical OS command injection (CWE-78) flaw in the …