Microsoft Unveils Always-On AI Agent Scout to Integrate With Teams, Outlook, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Microsoft has officially introduced Microsoft Scout, its first-ever “Autopilot” AI agent, a persistent, always-on autonomous assistant designed to operate continuously across Microsoft 365 apps without waiting to be prompted. Unveiled at Microsoft Build 2026 on June 2, …

New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. …

Hackers Using AI Tools to Automate Active Directory Attacks and EDR Evasion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A threat actor used AI-assisted tools to automate Active Directory discovery and test endpoint detection and response (EDR) evasion techniques, highlighting the rise of AI-supported post-exploitation frameworks. The activity was identified after a suspicious endpoint triggered alerts …

Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross-site scripting and response manipulation attacks in affected deployments. Tracked as CVE-2026-42253, …

Hackers Use YouTube and SEO Poisoning to Spread WeedHack Minecraft Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 Hackers are hiding dangerous malware inside what look like popular Minecraft mods and game clients, using YouTube videos and search engine tricks to pull unsuspecting players into their trap. The campaign, known as WeedHack, has been quietly …

Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A single forgotten development flag left active in production code silently handed Microsoft account tokens to any app on an Android device, exposing billions of users across six major Microsoft 365 apps to account takeover without any …

Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class as CVE-2026-33829 in the Snipping Tool, …

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single attacker on a …

1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a victim into clicking a single malicious link. The bug was …

WordPress Malware Abuses Steam Community Profiles for C2 Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community …