Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A dependency confusion vulnerability affecting Microsoft’s Azure Portal after the Microsoft Security Response Center (MSRC) closed the case, claiming the confirmed remote code execution evidence did not constitute an exploitable security issue. The vulnerability was uncovered by …

Mustang Panda Deploys PlugX RAT Through Multi-Stage LNK and PowerShell Attack Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A well-known Chinese state-sponsored threat group called Mustang Panda has been caught running a sophisticated cyberattack campaign using its signature remote access tool, PlugX. The group used a cleverly disguised fake browser update to trick users into …

TP-Link Router Vulnerability Allows Attackers to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed high-severity vulnerability in TP-Link routers could allow attackers to execute arbitrary system commands and fully compromise affected devices. Tracked as CVE-2026-5509, the flaw affects Archer BE450 v1 and Archer BE7200 v1 models. It has been assigned a …

Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical supply chain vulnerability in Claude Code’s GitHub Actions that could allow attackers to compromise any repository using Anthropic’s official CI/CD workflow, including Anthropic’s own infrastructure. The vulnerability, discovered by security researcher RyotaK of GMO Flatt …

Hackers Deploy AZUREVEIL Adaptix C2 Agent via Spearphishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly identified spearphishing campaign has been quietly targeting government officials, researchers, and technology workers in the Czech Republic and Taiwan. Threat researchers traced the operation to a China-linked threat actor, with the earliest known sample surfacing …

PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly analyzed remote access trojan called PHANTOMPULSE has drawn serious attention for its advanced approach to compromising Windows systems. The malware is the final-stage payload in a broader attack chain known as REF6598, a threat cluster …

Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore and also tracked as UNC1549 and Smoke Sandstorm, has a …

Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The flaw, tracked as CVE-2025-48595, was highlighted in the June 2026 …

Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive enterprise infrastructure. The issue, tracked as CVE-2026-4387, was discovered by …

Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot to hand over access. Over the weekend, high-value “OG” Instagram …