AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A new phishing campaign is turning a trusted remote access tool into a long term backdoor for espionage. Attackers hide behind fake invoices to slip past email filters, and once inside a network they rely on everyday …

Ubiquiti Disclosed 25 Security Vulnerabilities Across the UniFi Ecosystem

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 Ubiquiti has disclosed 25 security vulnerabilities affecting its UniFi ecosystem in Security Advisory Bulletin 066, including several critical flaws rated 9.9 and 10.0 on the CVSS v3.1 scale that could allow network-based attackers to fully compromise devices. …

STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A newly detailed cyber-espionage campaign is using fake remote desktop files and a recently patched WinRAR flaw to plant a stealthy backdoor called STOCKSTAY on computers in Ukraine. The malware disguises itself as everyday software, including stock …

Windows Adds Microsoft Execution Containers to Secure AI Agent Workflows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 Microsoft has introduced Microsoft Execution Containers (MXC), a new security capability designed to protect AI agent workflows on Windows, marking a significant step toward making Windows more trustworthy for autonomous systems. AI agents are rapidly evolving beyond …

U.S. Cyber Defense Agency Reportedly Using Anthropic’s Mythos to Audit Government Code Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly deploying Anthropic’s advanced AI model, Mythos, to audit federal government code repositories, signaling a growing reliance on artificial intelligence for proactive vulnerability discovery. According to Reuters, the initiative, CISA’s Attack …

Critical PHP PDO Driver Bugs Expose Firebird SQL Injection and PostgreSQL DoS Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A newly disclosed pair of flaws in PHP’s database driver layer shows that even mature code can hide dangerous surprises. The bugs live inside PHP Data Objects (PDO), the abstraction layer web applications use to talk to …

Microsoft Confirms Windows 11, 26H2 Comes With Change in Backup Policy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 Microsoft has confirmed a significant change to its Windows settings backup policy with the upcoming release of Windows 11 version 26H2, marking a shift toward improved system resilience and recovery capabilities. According to Microsoft, the Windows settings …

Hackers Use Recruiter Phishing Emails and Fake Career Pages to Harvest Gmail Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A new phishing campaign is targeting job seekers by posing as recruiters from recognizable brands. The scheme uses fake career pages and worded emails to trick people into handing over Gmail login credentials. What makes this campaign …

Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT. The campaign blends social engineering with legitimate remote support …

OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A newly disclosed vulnerability in the OpenAI Codex desktop application for macOS could allow attackers to exploit indirect prompt injection techniques to exfiltrate sensitive data, according to a recent entry in the GitHub Advisory Database. Tracked as …