U.S. Commerce Dept Imposes Export Controls on Anthropic’s Claude Mythos 5 and Fable 5

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 The Bureau of Industry and Security (BIS) has issued a landmark “Is Informed” letter to Anthropic CEO Dario Amodei, mandating that the company obtain an individually validated export license before sharing its Claude Mythos 5 and Claude …

Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A sophisticated supply chain attack has targeted the Mastra-AI npm ecosystem, with researchers from Microsoft and Socket identifying over 141 compromised packages designed to silently deploy an infostealer payload on developer machines, CI/CD runners, and build environments. …

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 AIRecon is an autonomous penetration testing agent that runs entirely offline, combining a self-hosted Ollama LLM with a Kali Linux Docker sandbox to automate end-to-end security assessments without exposing any data to the cloud. Developed by researcher …

Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows attackers to bypass authentication mechanisms under specific conditions by exploiting …

Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users are strongly advised to update immediately as several flaws impact …

Hackers Abuse Steam Workshop Application Wallpapers to Hijack Active Steam Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Threat actors have been abusing Valve’s Steam Workshop since late 2025, embedding malware inside Wallpaper Engine application wallpapers to hijack active Steam sessions and infect victims with backdoors, infostealers, and crypto miners, with 89% of targets located …

Hackers Using Claude and OpenAI’s Codex for Exploitation, and Data Exfiltration Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Hackers are increasingly abusing Anthropic’s Claude and OpenAI’s Codex agents to automate reconnaissance, exploitation, and data exfiltration, often by disguising real intrusions as “authorized red team” work. These AI coding assistants are being treated like full-fledged operators, …

Using Real-Time Network Monitoring to Spot Suspicious Application Behavior on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 In this guide, we will see how real-time network monitoring helps you spot suspicious application behavior on macOS, why traditional defenses leave a visibility gap, and how a lightweight monitoring tool can close it without turning your …

UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A sophisticated cybercriminal group has been quietly targeting law firms and professional services organizations across the United States since the beginning of 2026. The campaign is financially motivated and relies heavily on deception rather than technical exploits. …

Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A state-linked hacker group known as Ghostwriter has launched a wave of targeted phishing attacks aimed at Gmail users, disguising malicious emails as official security alerts from Google. The campaign is designed to trick recipients into handing …