Chrome Gemini Vulnerability Lets Attackers Access Victims’ Camera and Microphone Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Gemini Vulnerability A high-severity security vulnerability has been discovered in Google Chrome’s integrated Gemini AI assistant, exposing users to unauthorized camera and microphone access, local file theft, and phishing attacks, all without requiring any user interaction beyond launching the …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PoC Exploit Released Windows Error Reporting ALPC Privilege Escalation A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides within the Windows Error Reporting (WER) service. The vulnerability …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PoC Exploit Released Windows Error Reporting ALPC Privilege Escalation A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides …

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo Browser UXSS Flaw A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of …

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo Browser UXSS Flaw A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of …

MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MSHTML Framework 0-Day Exploited by APT28 A zero-day vulnerability in the Microsoft HTML (MSHTML) framework was actively exploited in the wild. The vulnerability, tracked as CVE-2026-21513, allows attackers to bypass security features and execute arbitrary files. With a CVSS score …

Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude AI Suffers Global Outage On March 2, 2026, Anthropic’s artificial intelligence assistant, Claude, experienced a significant global outage that disrupted workflows for users and developers worldwide. Organizations relying on the AI model for daily threat intelligence reporting, code generation, …

Criminal IP to Present Decision-Ready Threat Intelligence at RSAC™ 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, March 2nd, 2026, CyberNewswire March 23–26, 2026 | Booth N-6555, Moscone Center, San Francisco Criminal IP, an AI-powered cybersecurity platform specializing in Attack Surface Management (ASM) and Cyber Threat Intelligence (CTI), will participate in the …

GTFire Phishing Scheme Abuses Google Services to Evade Detection and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign called GTFire is abusing two of Google’s most trusted services — Firebase and Google Translate — to harvest login credentials from victims around the world. What makes this campaign dangerous is its ability to hide malicious …