SimpleHelp Authentication Bypass Vulnerability Exploited in the Wild to Deploy TaskWeaver Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software is being actively exploited in the wild. This enables attackers to deploy advanced malware, including a newly identified loader, TaskWeaver, and an information-stealing tool, …

Mustang Panda Abuses Zoho WorkDrive for Command-and-Control and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A China-aligned cyber espionage group known as Mustang Panda has been caught running two simultaneous attack campaigns against Indian government and energy targets, using a trusted cloud storage service as its hidden command center. The group deployed …

X Launches Hosted MCP Servers to Connect Cursor, Claude, and Other AI Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 X (formerly Twitter) has officially launched hosted Model Context Protocol (MCP) servers, enabling AI development tools such as Grok Build, Cursor, and Claude Desktop to seamlessly connect with the platform’s API and documentation. Announced on Tuesday, the …

New Windows Backdoor Mistic Enables In-Memory Code Execution and Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A newly identified Windows backdoor called Mistic has been quietly making its way through enterprise networks since April 2026, giving attackers persistent, low-profile access that is extremely difficult to detect. The malware has been spotted targeting organizations …

Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers …

Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The …

WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 WhatsApp introduces a new privacy update that lets users connect using unique handles, eliminating the need to share phone numbers with strangers or new group members. Earlier, we detailed that WhatsApp is preparing to roll out a …

EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 EvilTokens can keep serious account-takeover activity out of your SOC’s view by relying on “ghost” code that only surfaces after the browser decrypts it. Because of this, analysis that looks only at the static URL can overlook the …

U.S. Seizes Hundreds Domains Used to Stream World Cup Matches Illegally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 domains used to illegally stream FIFA World Cup 2026 matches, marking a significant crackdown on global digital piracy networks. The operation, conducted under “Operation …

Public PoC Released for Deserialization RCE Vulnerability in Splunk Secure Gateway

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 A public proof-of-concept (PoC) exploit has been released for CVE-2026-20251, a high-severity remote code execution (RCE) vulnerability affecting Splunk Secure Gateway (SSG). The flaw, carrying a CVSS score of 8.8, allows a low-privileged authenticated attacker to execute …