GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 GitHub has announced a major security-focused update to the Node Package Manager (npm), introducing breaking changes in the upcoming npm v12 release to reduce software supply chain attack risks significantly. The update, expected in July 2026, will …

Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A new study has revealed that advanced large language models (LLMs), particularly Anthropic’s Claude Mythos Preview, are dramatically accelerating the development of N-day exploits, reducing timelines from weeks to just hours and significantly increasing risk during the …

Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A network of Chinese-language online marketplaces operating on Telegram has quietly become one of the most powerful financial engines behind global cybercrime. These platforms, known as “guarantee” or dānbǎo (担保) marketplaces, use an escrow-based trust model to help criminals …

Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 Threat actors have begun actively exploiting a critical Ivanti Sentry command injection vulnerability just days after a proof-of-concept (PoC) exploit was made public, according to new internet scanning data from the Shadowserver Foundation. The flaw, tracked as …

PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A proof-of-concept (PoC) exploit has been released for a critical Linux kernel vulnerability, CVE-2026-46316, that enables a guest-to-host escape in KVM environments on arm64 systems. The flaw, named “ITScape,” allows attackers to break out of a virtual …

Oracle Emergency Security Update to Fix Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 Oracle has issued an emergency Security Alert to address a critical remote code execution vulnerability (CVE-2026-35273) affecting PeopleSoft Enterprise PeopleTools. The vulnerability carries a CVSS v3.1 score of 9.8, highlighting its severity and the urgent need for …

Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A high-severity vulnerability, CVE-2026-6973, in Ivanti Endpoint Manager Mobile (EPMM) could allow authenticated attackers to achieve remote code execution by injecting malicious Apache configuration directives. The flaw, assigned a CVSS score of 7.2, is classified as a …

Anthropic’s Claude Fable 5 Jailbroken to Generate Stack Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 Anthropic launched Claude Fable 5 on June 9, 2026, as the first publicly available model in its new Mythos class, its most capable AI to date, excelling in software engineering, knowledge work, and vision benchmarks. Researcher “Pliny …

Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 10, 2026 Hackers are turning everyday software searches into a trap. A sophisticated cryptojacking campaign is actively targeting users who search for popular PC utilities online, luring them into downloading malware-laced files that secretly mine cryptocurrency using their own …

Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 10, 2026 Hackers are using fake tax notification emails to trick Windows users into downloading dangerous multi-stage malware that runs entirely in memory, leaving almost no trace behind. The campaign, tracked as Operation TaxShadow, has been active since at least …