WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp Password Feature (Source: Wabetainfo) WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The update reveals that WhatsApp is actively developing an optional account password feature designed to add …

$10K+ Bounty Offered to Hacker Who Can Disconnect Ring Video Doorbells from Amazon Cloud

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

$10K+ Bounty Offered to Hacker Disconnect Ring from Amazon Cloud A newly launched bug bounty program is offering nearly $18,000 to anyone who can successfully disconnect Ring Video Doorbells from Amazon’s cloud servers while keeping the devices fully functional. This …

Google Chrome Emergency Security Update Patches Three High-Severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chrome Emergency Security Update Google has released a critical security update for its Chrome browser, pushing version 145.0.7632.116/117 to Windows and macOS users, while Linux users receive version 144.0.7559.116. The update, which is rolling out progressively over the coming …

GrayCharlie Injects Malicious JavaScript into WordPress Sites to Deliver NetSupport RAT and Stealc

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as GrayCharlie has been compromising WordPress websites since mid-2023, silently embedding malicious JavaScript to push malware onto visiting users. The group overlaps with the previously tracked SmartApeSG cluster, also called ZPHP or HANEMONEY. Its main tool …

Anthropic Claude Under Large Scale Distillation Attacks By Chinese AI Labs with 13 Million Exchanges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic today accused three prominent Chinese artificial intelligence companies DeepSeek, Moonshot AI, and MiniMax of running coordinated “distillation” campaigns to steal advanced capabilities from its Claude models. The San Francisco-based lab said the operations involved roughly 24,000 fraudulent accounts and …

Conduent Data Breach – Largest Data Breach in U.S. History As Ransomware Group Stolen 8 TB of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Conduent Data Breach Conduent Data Breach Notification Letters Sent to Millions as Ransomware Group Claims 8 Terabytes Stolen in One of the Largest U.S. Incidents. Letters began reaching affected individuals this month detailing a major data breach at Conduent Business …

New MIMICRAT Custom RAT Uncovered in Sophisticated Multi-Stage ClickFix Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has been uncovered, utilizing a deceptive technique known as “ClickFix” to distribute a custom remote access trojan dubbed MIMICRAT. This operation compromises legitimate websites to serve as delivery vectors, bypassing traditional security controls by relying …

Microsoft MFA Down – 504 Gateway Timeout Errors Disrupting MFA Access for U.S. Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a significant service degradation affecting Multi-Factor Authentication (MFA) across its Microsoft 365 suite, with users in the North America region reporting widespread 504 gateway timeout errors when attempting to authenticate into MFA-protected services. The incident, tracked …

New Phishing Framework Starkiller Proxies Real Login Pages to Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly sophisticated phishing framework named Starkiller has recently emerged, offering attackers an advanced method to steal credentials and bypass multi-factor authentication. Developed by a group known as Jinkusu, this malicious toolkit is sold as a commercial software-as-a-service product. Unlike …

North Korean Threat Actors Leverage Fake IT Worker Campaigns and Contagious Interview Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean nation-state threat actors have been running a two-part operation — posing as job recruiters while embedding fake workers inside real companies. Since at least 2022, these actors have tricked software developers into running malicious code during fake technical …