Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform first spotted in April 2026, was initially built to steal …

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with …

Hackers Abusing Microsoft Teams and Google Drive to Deploy Remote Access Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and cloud-based command-and-control to evade detection. In early April …

Cisco Unified Communications Manager Vulnerability Exposed Along With PoC Exploit Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tracked as CVE-2026-20230, with publicly available proof-of-concept (PoC) exploit code increasing the risk …

CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is actively exploited in the wild. The …

Hackers Use Fake Chrome Web Store Copyright Notices to Steal Google Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new phishing campaign is targeting Chrome extension developers using fake copyright removal notices that look like official messages from the Chrome Web Store. The scam tricks developers into entering their Google credentials on a counterfeit sign-in …

Acer Working to Patch Wave 7 Router 0-day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Acer is preparing a firmware update to address a critical zero-day vulnerability affecting its Wave 7 routers, following disclosure by independent security researcher Gergo Pap. The issue affects devices running firmware versions earlier than and poses a …

Bots Surpass Humans in Global Web Traffic for the First Time in Internet History

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 For the first time ever, automated bots have officially overtaken human users in global internet traffic, and the shift is accelerating faster than even industry leaders predicted. Bots Surpass Humans in Web Traffic According to data from …

Microsoft Unveils Always-On AI Agent Scout to Integrate With Teams, Outlook, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Microsoft has officially introduced Microsoft Scout, its first-ever “Autopilot” AI agent, a persistent, always-on autonomous assistant designed to operate continuously across Microsoft 365 apps without waiting to be prompted. Unveiled at Microsoft Build 2026 on June 2, …

New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. …