Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw found in a widely used WordPress plugin is putting thousands of websites at serious risk worldwide. Tracked as CVE-2026-1492, this vulnerability affects the User Registration & …

WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Telegram founder Pavel Durov has accused WhatsApp of perpetrating what he calls “the biggest consumer fraud in history,” alleging that the platform’s widely marketed end-to-end encryption (E2EE) claims are fundamentally …

Google Launches Gmail End-to-End Encryption for Android and iOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially rolled out End-to-End Encryption (E2EE) for the Gmail application on Android and iOS devices. This major update targets users utilizing Gmail client-side encryption. It allows organisations to …

Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google officially announced the public rollout of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146. According to the Google Account Security and Chrome teams, this major security …

Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent years, Endpoint Detection and Response (EDR) killers have become a standard, highly effective weapon in modern ransomware intrusions. Before launching their file-encrypting malware, cybercriminals routinely deploy specialized tools …

Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A single threat actor compromised nine Mexican government agencies and stole hundreds of millions of citizen records in a highly sophisticated cyberattack. The campaign, which ran from late December 2025 …

Anthropic Launches Claude Beta for Word, Bringing AI-Powered Editing to Microsoft Docs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has officially launched Claude for Word in public beta, bringing its AI assistant directly into Microsoft Word as a native sidebar add-in for Team and Enterprise users on both …

EngageSDK Vulnerability Exposes Millions of Crypto Wallet Users to Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security flaw found inside a widely used Android library called EngageSDK has put over 30 million cryptocurrency wallet users at risk of financial theft and personal data exposure. …

Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat group called Storm-2755 has launched a campaign that quietly reroutes employee salary payments to attacker-controlled bank accounts. Targeting Canadian workers, the group uses adversary-in-the-middle (AiTM) techniques …