Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming …

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting code, but by quietly choking their network bandwidth to near-zero …

Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg …

CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The …

New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 OpenAI has released ChatGPT Lockdown Mode, a new security feature designed to limit outbound network access and reduce the risk of data exfiltration from prompt-injection attacks. The feature is now available to eligible personal accounts, self-serve ChatGPT …

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, …

Top 5 Best Tools for Simulated DDoS Attacks in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses …

OWASP CVE Lite CLI – New Tool to Scan for Vulnerabilities in Your Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 CVE Lite CLI is a free, open-source vulnerability scanner officially recognized as an OWASP Incubator Project, designed to bring dependency security directly into developers’ terminals rather than leaving it buried in CI pipelines. Maintained by Sonu Kapoor …

Anthropic’s Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated]

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 Anthropic’s Claude platform suffered a significant service disruption on June 5, 2026, with elevated error rates impacting multiple frontier AI models and key services, including claude.ai, Claude API, Claude Code, and Claude Cowork, raising concerns not just …

Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 A deceptive Python package quietly made its way into the PyPI repository, putting thousands of developers at risk before it was caught and removed. The package, named “parsimonius,” was crafted to look almost identical to the widely …