Hacker Jailbreaks Claude AI to Write Exploit Code and Steal Government Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude AI Exploited A hacker exploited Anthropic’s Claude AI chatbot over a month-long campaign starting in December 2025, using it to identify vulnerabilities, generate exploit code, and exfiltrate sensitive data from Mexican government agencies. Cybersecurity firm Gambit Security uncovered the …

Hackers Can Abuse Cortex XDR Live Terminal Feature for C2 Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed research finding has revealed that Palo Alto Networks’ Cortex XDR Live Terminal feature can be turned into a command-and-control (C2) channel by attackers. Since this feature runs inside a trusted endpoint detection and response (EDR) agent, the …

Threat Actors Using Fake Avast Website to Harvest Users Credit Card Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are frequently refining their techniques to exploit consumer trust, and a highly sophisticated phishing campaign has recently surfaced that impersonates the cybersecurity firm Avast. This operation is designed to harvest sensitive financial credentials by tricking users into believing they …

SURXRAT Android RAT Attacking Users Gain Complete Device-Control and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The mobile threat landscape is witnessing a significant shift toward professionalized cybercriminal operations, driven by the increasing availability of sophisticated malicious tools. A new and potent threat known as SURXRAT has recently emerged, operating as a high-functioning Remote Access Trojan …

One Identity Appoints Michael Henricks as Chief Financial and Operating Officer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Alisa Viejo, CA, United States, February 25th, 2026, CyberNewswire One Identity, a trusted leader in identity security, today announced the appointment of Michael Henricks as Chief Financial and Operating Officer. This decision reflects the continued growth of the business and …

How SOC Analysts Can Save 28 Minutes Per Alert Review 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SOC analysts alert review How much time do you spend reviewing alerts that turn out to be harmless?  In many teams, a single alert takes around 30 minutes to investigate. Not because it’s complex, but because you have to pull …

OAuth Attacks in Entra ID Can Leverage ChatGPT to Compromise User Email Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are always looking for new ways to abuse trusted platforms, and Microsoft Entra ID is increasingly becoming a target through a technique known as OAuth consent abuse. A newly documented attack scenario shows how a malicious or overly …

CISA Confirms Active Exploitation of FileZen Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Confirms Exploit FileZen Vulnerability U.S. authorities have confirmed that threat actors are actively exploiting a critical vulnerability in FileZen by Soliton Systems K.K.. Due to the high risk associated with this flaw, CISA has officially added it to the …

Microsoft to Extends DLP Support for Copilot to Prevent Sensitive File Processing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Purview Data Loss Prevention (DLP) controls are being expanded to block Microsoft 365 Copilot from processing sensitivity-labeled files across all storage locations, including local devices. The change aims to close a critical governance gap in enterprise AI deployments. Previously, DLP …

SolarWinds Critical Serv-U Vulnerabilities Enables Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds Serv-U Vulnerabilities An urgent security update has been released for the Serv-U file server software to fix multiple critical vulnerabilities that could allow attackers to fully compromise affected systems. The latest release, Serv-U version 15.5.4, addresses four high-severity security …