Google Unveils Ransomware Detection and File Restoration for Google Drive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially moved its ransomware detection and file restoration features for Google Drive into General Availability. Originally launched in beta in September 2025, the updated security controls offer organizations enhanced defenses against malware attacks targeting local machines and cloud …

Hackers Deploy Telegram-Based ResokerRAT With Screenshot and Persistence Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new remote access trojan known as ResokerRAT has come to light, using Telegram’s bot API as its core communication channel to silently monitor and control infected Windows machines. What makes this threat stand out is that it does not …

Anthropic’s Claude Code Source Code Reportedly Leaked Via Their npm Registry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s proprietary Claude Code CLI tool has had its full TypeScript source code inadvertently exposed through a misconfigured npm package, after a security researcher discovered a leaked .map file referencing the unobfuscated codebase stored on Anthropic’s own cloud infrastructure. On …

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been disclosed in Smart Slider 3, one of the most widely used WordPress slider builder plugins. With over 800,000 active installations, this vulnerability leaves a massive number of websites exposed to severe data theft. Tracked as …

EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerous phishing toolkit has entered the cybercrime scene. In early 2026, a Phishing-as-a-Service platform called EvilTokens began circulating in underground cybercrime communities, offering criminals a ready-to-use kit built to steal Microsoft 365 accounts. Unlike most phishing tools …

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Users routinely trust AI assistants with highly sensitive information, including medical records, financial documents, and proprietary business code. Check Point Research recently disclosed a critical vulnerability in ChatGPT’s architecture that allowed attackers to extract this exact type of user data …

Apple New macOS Tahoe Feature Warns Users on ClickFix Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has introduced a new security mechanism in the macOS Tahoe 26.4 release candidate to protect users against social engineering campaigns known as ClickFix attacks. Discovered by users testing the latest OS build and highlighted in a popular Reddit post …

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical vulnerability affecting Citrix NetScaler products. Identified as CVE-2026-3055, this security flaw has been officially added to CISA’s Known Exploited Vulnerabilities (KEV) catalog following confirmed evidence …

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tax season brings a reliable wave of phishing attacks, but 2026 has already shown a bigger and more organized push than in previous years. Cybercriminals are actively impersonating the Internal Revenue Service (IRS), national tax authorities, and company HR departments …

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware named DeepLoad is targeting enterprise environments, turning a single user action into persistent, credential-stealing access that survives reboots and outlasts standard cleanup efforts. What sets this campaign apart is how every stage of the attack was …