Google Dismantles NetNut Residential Proxy That Hacked 2 Million Home Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 3, 2026 Google, working alongside the FBI, Lumen Technologies, and other industry partners, has taken action to dismantle the NetNut residential proxy network, also tracked as “Popa,” which is …

AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A stealthy campaign is turning trusted remote access software into a weapon against everyday users and businesses. Attackers have hidden the AsyncRAT trojan inside fake software installers, …

Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly uncovered phishing panel called ARToken is giving cybercriminals an easy way to steal Microsoft 365 login sessions without ever touching a password. The tool works …

Ousaban Malware Uses Phishing PDFs and VBS Downloader to Target Iberian Banking Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly documented campaign is quietly hijacking online banking sessions across Spain and Portugal, and it starts with something as ordinary as a broken PDF file. The …

Claude Cowork’s Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A vulnerability chain in Anthropic’s Claude Cowork allows an attacker with local code execution to escalate privileges and run arbitrary commands as root inside the product’s isolated …

CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a …

DHS Confirms Breach of Information-Sharing Network Platform HSIN

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform relied upon by federal, state, local, …

ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd …