Chrome Security Update Fixes 8 Vulnerabilities Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has rolled out an urgent security update for the Chrome browser to address eight high-severity vulnerabilities. These newly patched security flaws could allow threat actors to execute arbitrary code remotely, posing a significant risk to user data and system …

Hackers Attacking Android Users With Fake ChatGPT Invites to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have set their sights on Android users through a well-crafted phishing scheme that disguises malicious applications as beta-testing opportunities for ChatGPT and Meta advertising tools. What appears to be a legitimate app-testing invitation turns out to be a carefully …

NAKIVO Backup & Replication Launches v11.2 with Automated Real-Time Replication and VMware vSphere 9 Support 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NAKIVO v11.2 Sparks, Nevada — March 6, 2026  NAKIVO Inc. announced the release of NAKIVO Backup & Replication v11.2, offering expanded platform support, enhanced security and faster disaster recovery for organizations worldwide. This version is the product of a focused engineering roadmap, while …

511,000+ End-of-Life Microsoft IIS Instances Exposed Online, Secure Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive attack surface involving outdated Microsoft Internet Information Services (IIS) servers. During Shadowserver’s daily network scans on March 23, 2026, researchers identified over 511,000 End-of-Life (EOL) IIS instances actively connected to the internet. This widespread exposure presents a serious …

Mazda Data Breach Exposing Employee and Partner Records Via System Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mazda Motor Corporation has officially disclosed a security incident involving unauthorized external access to an internal warehouse management system, potentially exposing 692 personal data records of employees, group company staff, and business partners. The Japanese automaker published its formal breach …

Tax-Themed Google Ads Lead to BYOVD EDR Killer in Huntress-Traced Malvertising Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every April, millions of Americans rush to file taxes before the deadline — and attackers count on it. A large-scale malvertising campaign, active since at least January 2026, has been exploiting that urgency by placing fake tax form pages through …

SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated SEO poisoning campaign has been quietly targeting Windows users since at least October 2025, luring them into downloading trojanized installers for more than 25 popular software applications. The operation went undetected for roughly five months before investigators uncovered …

Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP QVR Pro Vulnerability QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote, unauthenticated attackers to gain unauthorized access to affected systems. Users relying on …

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Libyan oil refinery, a telecoms organization, and a state institution fell victim to a coordinated espionage campaign between November 2025 and February 2026. The attacks delivered AsyncRAT, a publicly available remote access Trojan with a documented history of use …

MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated macOS infostealer known as MioLab — also tracked as Nova — has emerged as one of the most advanced Malware-as-a-Service (MaaS) platforms targeting Apple users. Advertised on Russian-speaking underground forums, MioLab marks a shift in the threat landscape, …