ClawHub Vulnerability Let Attackers Manipulate Rankings to Become the #1 Skill

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security research team has uncovered a critical vulnerability in ClawHub, the public skills registry for the OpenClaw agentic ecosystem. This flaw allowed attackers to artificially inflate the download counts of malicious skills, thereby bypassing security checks and manipulating search rankings. …

Google Authenticator’s Hidden Passkey Architecture Could Open New Passwordless Attack Paths

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Passwordless authentication was supposed to mark the end of account takeovers. Designed to replace traditional passwords with cryptographic keys tied to physical devices, it promised a future where stolen credentials could no longer unlock user accounts. But a close examination …

FCC Blocks Foreign-made Consumer Routers Over Security Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Communications Commission (FCC) announced a major update to its Covered List, officially prohibiting the approval of new consumer-grade network routers produced in foreign countries. This regulatory action prevents these new devices from entering the United States market by …

LiteLLM Python Package With 95 Million Downloads Compromised by TeamPCP Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used open-source Python library was compromised on the Python Package Index (PyPI). Versions 1.82.7 and 1.82.8 of the package, which route requests across various LLM providers and have over 95 million monthly downloads, were found to contain a …

Kali Linux 2026.1 Released With 8 New Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kali Linux 2026.1 has officially been released, marking the first major update of the year for the popular penetration testing distribution. Designed for professionals engaged in technical security research and vulnerability analysis, this update features modern aesthetic enhancements, notable advancements …

Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack targeting Aqua Security’s widely used open-source vulnerability scanner, Trivy. A threat actor leveraged compromised credentials to distribute malicious releases, turning a trusted security tool into a mechanism for large-scale credential theft across CI/CD pipelines. The …

HackerOne Data Breach – Employees Data Stolen Following Navia Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackerOne recently disclosed a data breach affecting 287 of its employees following a cyberattack on its U.S. benefits administrator, Navia Benefit Solutions. The breach stemmed from a Broken Object Level Authorization (BOLA) vulnerability in Navia’s API, which exposed the sensitive …

Dell Wyse Management Vulnerabilities Enables Complete System Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent security analysis has revealed how chaining seemingly minor logic flaws in Dell Wyse Management Suite (WMS) On-Premises can result in a complete system compromise. Security researchers demonstrated that combining two distinct vulnerabilities allows an unauthenticated attacker to bypass …

Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals behind Tycoon2FA, a phishing-as-a-service (PhaaS) platform, have resumed targeting cloud accounts with near-full force despite a coordinated law enforcement takedown on March 4, 2026. Europol, working alongside authorities from six countries, seized 330 domains that formed the backbone of …

Threat Actors Continuously Attacking MS-SQL Servers to Deploy ICE Cloud Scanner

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent threat actor known as Larva-26002 has been continuously targeting poorly managed Microsoft SQL (MS-SQL) servers, this time deploying a new scanner malware called ICE Cloud Client. The campaign has been active since at least January 2024 and continues …