Fake Huorong Download Site Used to Deploy ValleyRAT Backdoor in Targeted Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of attackers has built a fake version of the Huorong Security antivirus website to trick users into downloading ValleyRAT, a Remote Access Trojan (RAT) built on the Winos4.0 framework. The campaign is linked to the Silver Fox APT …

ClickFix Infostealer Campaign Uses Fake CAPTCHA Lures to Compromise Victims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign has emerged, leveraging fake CAPTCHA lures to deceive users and deploy a stealthy information stealer. Identified in early 2026, this activity shares significant behavioral patterns with the ClickFix campaign that previously targeted restaurant reservation systems …

Multiple VMware Aria Vulnerabilities Allow Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware Aria Vulnerabilities RCE Attack Broadcom issued security advisory VMSA-2026-0001 on February 24, 2026, disclosing three vulnerabilities in VMware Aria Operations that pose risks, including remote code execution. Organizations using affected products should prioritize patching to mitigate potential exploits. VMware …

Elon Musk Accuses Anthropic of Stealing Data in a Massive Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elon Musk Accuses Anthropic Stealing Data The CEO of Tesla and xAI recently stated that the artificial intelligence company Anthropic has stolen large amounts of data to train its models. Musk claims this data theft occurred on a massive scale, …

OpenClaw Releases 2026.2.23 Released With Security Updates and New AI features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw 2026.2.23 Released OpenClaw, the open-source personal AI assistant with over 215,000 GitHub stars, has released version 2026.2.23, emphasizing robust security hardening alongside advanced AI integrations. This update addresses multiple vulnerabilities and introduces features like Claude Opus 4.6 support, making …

Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early February 2026, a significant cybersecurity threat emerged involving the sophisticated use of Large Language Models (LLMs) in active intrusion campaigns. A misconfigured server exposed a detailed software pipeline where threat actors integrated DeepSeek and Claude into their attack …

WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp Password Feature (Source: Wabetainfo) WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The update reveals that WhatsApp is actively developing an optional account password feature designed to add …

$10K+ Bounty Offered to Hacker Who Can Disconnect Ring Video Doorbells from Amazon Cloud

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

$10K+ Bounty Offered to Hacker Disconnect Ring from Amazon Cloud A newly launched bug bounty program is offering nearly $18,000 to anyone who can successfully disconnect Ring Video Doorbells from Amazon’s cloud servers while keeping the devices fully functional. This …

Google Chrome Emergency Security Update Patches Three High-Severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chrome Emergency Security Update Google has released a critical security update for its Chrome browser, pushing version 145.0.7632.116/117 to Windows and macOS users, while Linux users receive version 144.0.7559.116. The update, which is rolling out progressively over the coming …

GrayCharlie Injects Malicious JavaScript into WordPress Sites to Deliver NetSupport RAT and Stealc

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as GrayCharlie has been compromising WordPress websites since mid-2023, silently embedding malicious JavaScript to push malware onto visiting users. The group overlaps with the previously tracked SmartApeSG cluster, also called ZPHP or HANEMONEY. Its main tool …