SuperClaw – Open-Source Framework to Red-Team AI Agents for Security Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Superagentic AI has released SuperClaw, an open-source, pre-deployment security testing framework built specifically for autonomous AI coding agents. Announced in late 2025, SuperClaw addresses a growing blind spot in enterprise AI adoption: agents are routinely deployed with broad tool access …

Cybersecurity Companies’ Stocks Fall Sharply as Anthropic Releases Claude Security Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Security Tool Stocks Impacted Shares of major cybersecurity companies nosedived on Friday after AI startup Anthropic unveiled Claude Code Security, a new AI-powered tool capable of autonomously scanning codebases for software vulnerabilities and suggesting targeted patches sparking fears that …

New Shai-Hulud–like npm Worm Attack 19+ Packages to Steal dev/CI Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shai-Hulud–like npm Worm Attack A new supply chain worm is actively targeting the npm ecosystem, with a research team identifying at least 19 malicious npm packages designed to steal developer and CI/CD secrets and automatically spread across repositories and workflows. …

Anthropic Launches Claude Code Security to Scan Codebases for Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Code Security A new feature inside Claude Code enables developers and security teams to identify and remediate vulnerabilities across their codebases, known as Claude Code Security. Currently available in a limited research preview, the tool offers AI-powered code scanning …

‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

February 20, 2026 0 Comments Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering …

PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PayPal Data Breach PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, …

Grandstream VoIP Phones Vulnerability Allows Attackers to Gain Root Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VoIP desk phones are trusted devices, but many are managed like office furniture. A newly disclosed flaw in Grandstream phones shows how a simple network-facing bug can turn a handset into an entry point for eavesdropping and wider access. In …

CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Python-based infostealer called CharlieKirk Grabber has been identified targeting Windows systems, with a focused goal of stealing stored login credentials, browser cookies, and session data. The malware is built to work as a “smash-and-grab” threat — it launches …

Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins Vulnerability Exposes XSS Attacks Security Advisory has revealed multiple vulnerabilities in Jenkins Core, including a stored Cross-Site Scripting (XSS) flaw that could expose build environments to severe security risks. The issues, identified as CVE-2026-27099 and CVE-2026-27100, were responsibly disclosed under the Jenkins Bug Bounty …

Critical Vulnerabilities in VS Code Extensions Threaten 128 Million Developer Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

128 Million Users at Risk VS Code Extensions Flaws Three critical vulnerabilities have been found in four popular Visual Studio Code extensions. These extensions have been downloaded over 128 million times. The vulnerabilities are identified as CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717. …