‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role …

Hackers Abuse GitHub Issue Notifications to Phish Developers Through Malicious OAuth Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated phishing technique that targets software developers by abusing GitHub’s own notification system to deliver malicious OAuth app authorization requests. This attack is particularly dangerous …

CISA Warns of Cisco Catalyst SD-WAN Manager Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added three critical Cisco Catalyst SD-WAN Manager vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to act immediately. All three flaws were added …

6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than 6,000 internet-exposed Apache ActiveMQ instances are still vulnerable to CVE-2026-34197. This newly tracked security flaw has now been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities …

Gentlemen RaaS Attacking Windows, Linux With additional locker written in C for ESXi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware-as-a-service (RaaS) operation known as “The Gentlemen” has emerged as a serious threat to corporate networks worldwide. Since appearing around mid-2025, this group has rapidly grown into a …

AI-Powered Exploitation May Collapse the Patch Window for Defenders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence is reshaping cybercrime in ways that defenders can no longer treat as distant or theoretical. New frontier AI models are showing a growing ability to find software flaws, …

Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to hijack AI coding …

SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixel-perfect clone …

PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes by luring them …

iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers, working in partnership with OpenAI, have uncovered a fascinating and severe vulnerability in iTerm2, a widely used macOS terminal emulator. According to Califio, the flaw abuses the application’s …