Docker Open Sources Production-Ready Hardened Images for Free

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Docker has announced a significant shift in its container security strategy, making its Docker Hardened Images (DHI) freely available to all developers. Previously a commercial-only offering, DHI provides a set of secure, …

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. …

Lies-in-the-Loop Attack Turns AI Safety Dialogs into Remote Code Execution Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered attack technique has exposed a critical weakness in artificial intelligence code assistants by weaponizing their built-in safety features. The attack, known as Lies-in-the-Loop, manipulates the trust users …

Multiple Exim Server Vulnerabilities Let Attackers Seize Control of the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at the National Institute of Standards and Technology (NIST) have uncovered critical security flaws in the Exim mail server. That could allow remote attackers to take complete control …

Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now targeting Microsoft 365 accounts using a growing attack method known as OAuth device code phishing. This technique takes advantage of the OAuth 2.0 device authorization flow, …

DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and ominous player has emerged in the rapidly expanding landscape of “Shadow AI.” Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the …

Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, …

100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that attackers are actively exploiting …

Claude Opus 4.5 Now Integrated with GitHub Copilot

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitHub has announced the general availability of Claude Opus 4.5, Anthropic’s advanced AI model, across its Copilot platform. This integration enhances AI capabilities for developers using GitHub’s code assistance tools. …

Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has begun deploying Baseline Security Mode across Microsoft 365 tenants, a new dashboard in the M365 Admin Center that centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and …