Python Vulnerability Allows Out-of-Bounds Write on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Python’s Windows asyncio implementation, allowing attackers to trigger out-of-bounds memory writes through a missing boundary check in network socket operations. The vulnerability, tracked as CVE-2026-3298, carries a high severity rating. It exclusively affects Windows platforms and was publicly …

Udemy Data Breach – ShinyHunters Allegedly Claims Compromise of 1.4M User Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal group ShinyHunters has claimed responsibility for a major data breach targeting Udemy, Inc. (udemy.com), one of the world’s largest online learning platforms, and has alleged the compromise of over 1.4 million records containing personally identifiable information (PII) …

Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing …

Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attackers are no longer relying only on widely known tools to steal data. Affiliates linked to the Trigona ransomware group have taken a more calculated approach by building their own custom data exfiltration tool, one that gives them greater …

Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major investigation has revealed that sophisticated threat actors are exploiting fundamental vulnerabilities in global mobile networks to track users worldwide. By abusing legacy 3G SS7 and 4G Diameter signaling protocols, hackers are successfully bypassing telecom firewalls to conduct silent, …

Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a known issue preventing some users from joining Microsoft Teams meetings on Windows devices, following a recent update to the Microsoft Edge browser. The disruption is affecting organizations, including those using NHSmail infrastructure, with reports indicating …

Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation, a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software …

North Korean Hackers Use Fake IT Worker Scheme to Infiltrate Companies and Evade Sanctions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea has been running one of the most quietly effective cyber fraud operations in recent years. State-sponsored operatives working for the Pyongyang regime have been posing as legitimate remote IT workers to get hired by companies around the world, …

Hackers Abuse Fake Wallpaper App and YouTube Channel to Spread notnullOSX Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new macOS malware called notnullOSX has surfaced in early 2026, specifically built to steal cryptocurrency from Mac users who hold digital assets worth more than $10,000. The threat is real, active, and carefully constructed to look completely legitimate at …

Fake TradingView AI Agent Site is Delivering Needle Stealer Malware via Fake TradingClaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign is tricking traders into downloading a data-stealing tool by impersonating the popular financial platform TradingView. Attackers set up a fake website promoting something called TradingClaw, which they describe as an AI-powered trading assistant. Once a visitor …