Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot to hand over access. Over the weekend, high-value “OG” Instagram …

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s …

IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The flaw, tracked as CVE-2026-8633, affects environments that use the optional …

Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, or admin access required. Security researchers at Sansec uncovered an …

Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. The campaign …

SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan’s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 …

Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A newly disclosed critical vulnerability in Plesk, tracked as CVE-2026-44962, is raising serious security concerns after researchers confirmed it can allow authenticated users to execute arbitrary operating system commands on affected servers. The issue, published in the …

Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 Iran-linked hackers have launched a sweeping campaign of digital destruction across the United States and the Middle East, wiping IT systems, erasing backups, and dismantling recovery infrastructure at multiple organizations. The attacks, carried out under a pro-Iranian …

New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. Using a combination of fake browser update pages and a social engineering trick known as ClickFix, …

Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a service disruption affecting users attempting to set up multi-factor authentication (MFA) or access the self-service sign-in portal at mysignins.microsoft.com. The issue was officially acknowledged by the company’s Microsoft 365 Status account on X (formerly Twitter) …