Hackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 Threat actors are actively exploiting CVE-2026-46817, a critical unauthenticated remote takeover vulnerability in Oracle E-Business Suite (EBS), with live attack activity captured across honeypot infrastructure over the weekend of June 27–28, 2026. CVE-2026-46817 is a critical-severity flaw …

Critical Dell Wyse Vulnerabilities Enable Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 Dell Technologies has released a critical security advisory addressing multiple vulnerabilities in its Wyse Management Suite (WMS), warning that attackers could exploit these flaws to execute arbitrary code on affected systems. The vulnerabilities affect Dell Wyse Management …

Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file. The vulnerability, tracked as CVE-2025-60727, affects multiple versions of Microsoft Office and underscores the continued risk posed by …

Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 A critical security vulnerability in Google’s Gemini CLI has been disclosed, allowing attackers to execute arbitrary code in certain CI/CD environments, particularly GitHub Actions workflows. The issue, tracked as CVE-2026-12537, impacts multiple versions of the Gemini CLI …

Russia-Linked Turla Uses Compromised Infrastructure to Deploy STOCKSTAY in Ukraine Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 Russia-linked threat group Turla has been quietly expanding its espionage arsenal with a new backdoor called STOCKSTAY, actively targeting government and military organizations in Ukraine since at least December 2022. The malware is built in .NET and …

ClawHub Skills Expose AI Agents to Remote Control Backdoors and Data Theft Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 AI-powered agents are no longer just answering questions. They now take actions, manage files, and run code on behalf of users. That shift has opened a dangerous new door, and attackers have already walked through it. Malicious …

LLM-Generated Mythic Agents Enable Disposable Red-Team Tooling From Prompt to Deployment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 Red teamers and offensive security researchers have entered a new era where AI can write functional attack tools from a single sentence. A concept known as “disposable tooling” is now taking shape, and the implications for defenders …

Millenium RAT Rewritten in C++ Infects 62,000+ Devices Across 160 Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 A remote access trojan known as Millenium RAT has been quietly spreading across the globe, and the numbers are hard to ignore. Over 62,000 devices have been compromised across more than 160 countries, with no signs of …

UNC1151 Ghostwriter Hackers Target Belarusian Politician in Gmail Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known hacker group called UNC1151, also widely known as Ghostwriter, has been caught running a targeted phishing campaign against a prominent Belarusian pro-democracy politician. The group, which has long been tied to the interests of the Belarusian government and, …

China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 29, 2026 Zhipu AI’s open-weight GLM-5.2 model is reportedly performing on par with Anthropic’s restricted Claude Mythos in specific cybersecurity and software vulnerability detection tasks, a development that is intensifying concerns inside the U.S. government about the effectiveness of …