Trump Bans Anthropic AI in Federal Agencies — Pentagon Flags Claude as Security Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. government has taken unprecedented action against domestic AI firm Anthropic, directing all federal agencies to immediately stop using its AI model Claude and officially designating the company a …

Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

For years, taking down a botnet meant finding its command-and-control (C2) server, seizing the domain, and watching the network go dark. Law enforcement used this method to dismantle major operations …

Vshell Gains Traction Among Threat Actors as an Alternative to Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Go-based command-and-control (C2) framework originally marketed within Chinese-speaking offensive security communities has been quietly expanding its reach, drawing growing attention from threat actors seeking flexible and cost-effective alternatives to …

Critical Trend Micro Apex One Vulnerabilities Allows Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro Apex One Vulnerabilities Trend Micro has released fixes for multiple Apex One vulnerabilities, ranging from High to Critical severity, including management console issues that can lead to remote code execution …

Malicious Go Crypto Module Steals Passwords and Deploy Rekoobe Backdoor in Developer Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Go Crypto Module Steals Passwords and Deploys Rekoobe Backdoor in Developer Environments A newly discovered supply chain attack is putting Go developers at serious risk. A threat actor published …

Infostealers Fuel Large‑Scale Brute‑Forcing of Corporate SSO Gateways Using Stolen Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A wave of credential stuffing attacks has exposed a troubling shift in how threat actors are breaking into corporate networks — not by exploiting software vulnerabilities, but by simply logging …

FreeBSD Vulnerability Allow Attackers to Crash the Entire System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreeBSD Vulnerability Administrators must urgently patch a critical vulnerability that allows attackers to escape isolated jail environments. Tracked as CVE-2025-15576, the flaw enables a dangerous jailbreak condition despite often being …

Critical Zyxel Vulnerabilities Exposes Routers to Remote Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel Vulnerabilities Critical firmware updates have been released to address multiple serious vulnerabilities in networking devices, including 4G LTE/5G NR CPEs, DSL/Ethernet CPEs, Fiber ONTs, Security Routers, and Wireless Extenders. …

Juniper Networks PTX Vulnerability Enables Full Router Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major networking vendor has issued an out-of-cycle security bulletin to address a critical vulnerability in its Junos OS Evolved software, specifically affecting PTX Series platforms. This flaw, identified as …

Microsoft Defender Expands URL Click Alerts to Include Microsoft Teams for Enhanced Security Visibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is strengthening its cybersecurity ecosystem by extending Microsoft Defender for Office 365 (MDO) URL click alerts to Microsoft Teams. Previously focused on email threats, this update gives security teams …