Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser’s link preview less useful …

New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing is arriving via trusted email systems. Instead of using obvious malicious addresses, attackers send ordinary account alerts, invoices and renewal notices that lead victims into web-based traps. The approach …

Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns …

Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities in The Events Calendar WordPress plugin could allow unauthenticated attackers to take over vulnerable websites. The flaws affect more than 600,000 active installations. They can lead to …

Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red Heron, …

Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity Telegram Desktop vulnerability let attackers hide JavaScript in bot-created inline keyboard buttons and steal chat content when victims exported conversations as HTML files. Telegram fixed the issue in …

Hackers Use Autonomous AI Agents to Harvest Thousands of Credentials in Under 6 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are using autonomous AI agents to turn compromised cloud systems into rapid credential-harvesting platforms. In a newly documented case, a suspected financially motivated actor planned, built, and ran a …

Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight …