Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clawdbot, the surging open-source AI agent gateway, faces escalating security concerns, with 900+ unauthenticated instances exposed online and multiple code flaws that enable credential theft and remote code execution. Clawdbot …

800K+ GNU InetUtils telnetd Instances Exposed to RCE Attacks – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the telnetd component of GNU Inetutils has exposed approximately 800,000 internet-accessible Telnet instances to unauthenticated remote code execution (RCE). Tracked as CVE-2026-24061 with a …

Curl to End Bug Bounty Following Low-Quality AI-Generated Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The curl project ended its bug bounty program in January 2026 because it received too many low-quality and useless bug reports. The decision reflects growing frustration within the open-source security …

New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Browser attacks have become far more dangerous and organized than before. A new threat called Stanley, discovered in January 2026, shows just how serious the problem has become. This malware-as-a-service …

Lazarus Hackers Actively Attacking European Drone Manufacturing Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus, a sophisticated North Korean-aligned hacking group also known as HIDDEN COBRA, has launched a new wave of targeted attacks against European drone manufacturers and defense contractors. The campaign, tracked …

MITRE Releases New Cybersecurity Framework to Protect the Embedded Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Embedded Systems Threat Matrix™ (ESTM) framework was introduced to help secure embedded systems used in critical infrastructure and defense technologies across the U.S. Developed collaboratively with the Air …

New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea’s Lazarus Group has launched a sophisticated supply chain attack targeting software developers through a campaign called “Fake Font.” The threat actors are using fake job interviews and malicious …

‘SyncFuture’ Campaign Weaponizing Legitimate Enterprise Security Software to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, threat researchers uncovered an alarming espionage operation targeting residents of India through sophisticated phishing campaigns. The attack, dubbed SyncFuture, demonstrates how cybercriminals can abuse legitimate business software …