Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code secrets. F5 honeypot sensors recorded …

UK Government Begins Moving 23 Million Users Away From Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public services. The deployment covers everything from …

Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access information stored on the console. Tracked as CVE-2026-82079, …

Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or …

AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the AWS Systems Manager Agent could let authenticated attackers bypass remote-host port-forwarding restrictions and access sensitive link-local services, including the Amazon EC2 Instance Metadata Service. The …

Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called “Twitch Enhanced Viewer | JeetBot,” …

WhatsApp’s New Restricted Chat Feature Locks Conversation on Your Primary Phone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp is developing a new privacy control called Restricted Chat that will keep selected conversations accessible only from a user’s primary mobile phone. The feature is designed to prevent protected …

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can …

New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control. Tracked as CVE-2026-43502, the flaw was demonstrated through an exploit called ZcopyReaper …

One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A single click on a malicious link could have given attackers a direct path into Windows systems running Sogou Input Method. The flaw turned a commonly installed Chinese-language typing tool …