MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated macOS malware called MacSync has emerged as a dangerous new threat targeting cryptocurrency users through deceptive social engineering tactics. The infostealer operates as an affordable Malware-as-a-Service tool designed …

Hackers Can Use GenAI to Change Loaded Clean Page Into Malicious within Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and alarming threat has emerged in the cybersecurity landscape where attackers combine artificial intelligence with web-based attacks to transform innocent-looking webpages into dangerous phishing tools in real time. …

New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new generation of phishing kits designed specifically for voice-based attacks has emerged as a growing threat to enterprise users across major technology platforms. Okta Threat Intelligence discovered multiple …

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js has updated its HackerOne vulnerability disclosure program to require a minimum Signal score of 1.0, aiming to reduce low-quality submissions and improve processing efficiency. Node.js has implemented a new …

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security feature for Teams Calling now alerts users to suspicious external calls that try to impersonate trusted organizations. The feature will begin deployment in mid-February 2026 for Targeted …

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass vulnerability, with a new automated campaign targeting even fully patched FortiGate devices. Cybersecurity firm Arctic Wolf first observed the attacks …

New Windows Notepad and Paint Update Brings More Useful AI Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence (AI) features have been added to Windows 11 Notepad and Paint for Canary and Dev Channel users, turning them into cloud-connected tools that require sign-in. The Notepad update …

TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TrustAsia has revoked 143 SSL/TLS certificates following the discovery of a vulnerability in its LiteSSL ACME service. The flaw allowed for the improper reuse of domain validation data across different …

HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability affecting multiple storage platforms could allow remote attackers to gain administrative access without physical interaction. The flaw, tracked as CVE-2026-23594, impacts HPE Alletra 6000, Alletra …