MetaMask Users Targeted with Phishing Emails Containing Forged Security Report to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is targeting MetaMask users through carefully crafted emails that contain fake security incident reports designed to manipulate victims into compromising their accounts. The attack leverages social engineering tactics by creating a false sense of urgency around …

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paloalto to Acquire Koi Security Palo Alto Networks announced a definitive agreement to acquire Koi Security, a leading innovator in Agentic Endpoint Security, marking a major expansion of its AI‑driven defense portfolio. The move underscores Palo Alto’s commitment to securing the …

Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer Use, and 1M Token Context Window

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Sonnet 4.6 Released Anthropic has officially launched Claude Sonnet 4.6, its most capable mid-tier model to date, delivering a comprehensive upgrade across coding, computer use, long-context reasoning, agent planning, knowledge work, and design, all at the same price point …

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Adds Windows Video ActiveX Control RCE Flaw A long-dormant Microsoft Windows vulnerability, CVE-2008-0015, has been added to the Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw, first disclosed more than a decade …

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Firefox 0-Day RCE A critical Remote Code Execution (RCE) vulnerability in Mozilla Firefox was caused by a single-character typo in the SpiderMonkey JavaScript engine’s WebAssembly garbage collection code, where a developer mistakenly typed “&” (bitwise AND) instead of “|” (bitwise …

New Phishing Campaign Targets Booking.com Partners and Customers in Multi-Stage Financial Fraud Scheme

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Booking.com‑themed phishing campaign is abusing trust in travel brands to steal money and sensitive data from both hotels and guests. The scheme can start as a service message, but it can end with payment fraud and card exposure. …

CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chromium 0-Day Vulnerability An urgent warning regarding a newly discovered zero-day vulnerability in Google Chromium, which is reportedly under active exploitation in the wild. The vulnerability, tracked as CVE-2026-2441, affects Chromium’s CSS (Cascading Style Sheets) engine and can enable remote …

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft VS Code Extension 11M Downloads A critical vulnerability discovered in Microsoft’s popular Visual Studio Code (VS Code) Live Preview extension, downloaded over 11 million times, exposes developers to one-click cross-site scripting (XSS) and local file exfiltration attacks. The flaw, now patched, was discovered by …

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign named ‘CRESCENTHARVEST’ has surfaced, strategically exploiting the geopolitical unrest in Iran to target dissidents and protest supporters. This cyberespionage operation leverages social engineering to deploy a dual-purpose threat capability, functioning as both a remote access …

Cybercriminals Leverage Atlassian Cloud for Spam Campaigns Redirecting Targets to Fraudulent Investment Schemes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated spam campaign leveraging the trusted infrastructure of Atlassian Cloud. By abusing legitimate features within the platform, attackers are effectively bypassing traditional email security controls to reach high-value targets. This campaign focuses on redirecting users to …