Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the platform’s outsourcing partner, Telus. The breach, which reportedly occurred on …

AstraZeneca Data Breach – LAPSUS$ Group Allegedly Claims Access to Internal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective LAPSUS$ has resurfaced, allegedly claiming responsibility for a significant data breach involving the multinational pharmaceutical and biotechnology company AstraZeneca. The threat actors are currently attempting to sell a compressed 3GB internal data dump, signaling a potential …

Malicious Script Injection in Trivy Compromise Enables Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Script Injection in Trivy Compromise A sophisticated supply chain attack targeting the official Trivy GitHub Action (aquasecurity/trivy-action) has compromised continuous integration and continuous deployment (CI/CD) pipelines globally. Disclosed in late March 2026, this incident marks the second distinct compromise …

FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FBI, CISA Warn Russian Hackers The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread phishing campaign. The alert warns that Russian Intelligence Services are actively …

Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel update rolls out versions 146.0.7680.153 and 146.0.7680.154 for Windows and …

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score of …

Anthropic Launches Projects Feature for Claude Cowork Desktop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic is expanding Claude Cowork Desktop with a new Projects feature designed to keep files, instructions, and task context organized inside a single workspace. For paid users, the update makes it easier to start from scratch, import an existing chat, …

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 March Update Breaks Teams Microsoft has acknowledged a significant bug introduced by its March 2026 cumulative update that is preventing users from signing into Microsoft Teams Free, OneDrive, and several other Microsoft applications on Windows 11 devices. The …

Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sweeping cyberattack campaign has compromised more than 7,500 Magento-powered e-commerce websites since late February 2026, with attackers uploading hidden malicious files into publicly accessible web directories across thousands of domains. The attack has spread to over 15,000 hostnames, affecting …

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified variant of the VoidStealer infostealer has drawn serious attention from the security community after it became the first malware known to bypass Google Chrome’s Application-Bound Encryption (ABE) without requiring code injection or elevated system privileges. The variant, …