Fake Income Tax Assessment Notice Delivers RAT-Like Malware to Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Cybercriminals are now using fake government tax notices to push dangerous malware onto Windows computers, and the tactic is proving alarmingly effective. A newly uncovered campaign targets …

PoC Exploit Released for Microsoft Exchange Server Elevation of Privilege Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A public proof-of-concept exploit is now available for CVE-2026-45504, a high‑severity server-side request forgery vulnerability in Microsoft Exchange Server that enables privilege escalation via arbitrary file reads. …

Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands …

White House Orders Federal Agencies to Migrate Systems to Post-Quantum Cryptography

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The White House has issued a major executive order directing U.S. federal civilian agencies to migrate high‑value systems to post‑quantum cryptography (PQC), with firm deadlines of 2030 for key establishment …

PoC Exploit Released for libssh2 Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A public proof-of-concept (PoC) exploit for the critical libssh2 remote code execution vulnerability tracked as CVE-2026-55200 is now available, significantly increasing the risk of real‑world attacks against …

Browser-in-the-Browser Kit Uses Fake Software Errors to Deliver Malware Installers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified attack campaign is using a sophisticated Browser-in-the-Browser (BitB) kit to trick users into downloading malware disguised as legitimate software installers. The technique combines convincing …

GhostShell Malware Uses mTLS Implant and Telegram Dead-Drop to Target Ukrainian Drone Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified malware cluster known as GhostShell has been found actively targeting Ukraine’s drone operations and its broader defense supply chain. The campaign uses a sophisticated …

Red-Team AI Tool Vulnerabilities Let Attackers Exfiltrate API Keys and Compromise Operators’ Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A first-of-its-kind security analysis of 12 widely deployed agentic offensive-security tools reveals critical architectural flaws that allow adversaries to steal LLM API keys, establish persistent footholds, and …

Hackers Exploit Unpatched SharePoint Servers to Deploy Ransomware and Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Unpatched on-premises SharePoint servers have become a prime target for sophisticated threat actors using known security flaws to break in, plant ransomware, and leave behind hidden backdoors. …

Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A malicious AI “skill” created as part of a controlled security experiment has exposed critical weaknesses in modern AI agent ecosystems, successfully bypassing security scanners and compromising …