Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A single forgotten development flag left active in production code silently handed Microsoft account tokens to any app on an Android device, exposing billions of users across …

Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is …

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, …

1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 3, 2026 A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a …

WordPress Malware Abuses Steam Community Profiles for C2 Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to …

Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Attackers Hide Malicious Traffic in Cloud Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious …

Red Hat Confirms Supply Chain Compromise of @redhat-cloud-services npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Red Hat has officially confirmed a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace, disclosed publicly on June 1, 2026. A compromised GitHub …

Russia Says Foreign Spyware Found on High-Ranking Officials’ Mobile Phones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Russia’s Federal Security Service (FSB) has claimed it disrupted a large-scale cyber-espionage operation involving the deployment of advanced spyware on mobile devices used by high-ranking government officials. …

Halo Security Honored with 2026 MSP Today Product of the Year Award

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Miami Beach, FL, USA, June 2nd, 2026, CyberNewswire Attack Surface Management Platform Recognized for Exceptional Innovation and Successful Deployment Through The Channel Halo Security today announced that …