GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 GitHub has announced a major security-focused update to the Node Package Manager (npm), introducing breaking changes in the upcoming npm v12 release to reduce software supply chain …

Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A new study has revealed that advanced large language models (LLMs), particularly Anthropic’s Claude Mythos Preview, are dramatically accelerating the development of N-day exploits, reducing timelines from …

Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A network of Chinese-language online marketplaces operating on Telegram has quietly become one of the most powerful financial engines behind global cybercrime. These platforms, known as “guarantee” …

Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 Threat actors have begun actively exploiting a critical Ivanti Sentry command injection vulnerability just days after a proof-of-concept (PoC) exploit was made public, according to new internet …

PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A proof-of-concept (PoC) exploit has been released for a critical Linux kernel vulnerability, CVE-2026-46316, that enables a guest-to-host escape in KVM environments on arm64 systems. The flaw, …

Oracle Emergency Security Update to Fix Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 Oracle has issued an emergency Security Alert to address a critical remote code execution vulnerability (CVE-2026-35273) affecting PeopleSoft Enterprise PeopleTools. The vulnerability carries a CVSS v3.1 score …

Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 11, 2026 A high-severity vulnerability, CVE-2026-6973, in Ivanti Endpoint Manager Mobile (EPMM) could allow authenticated attackers to achieve remote code execution by injecting malicious Apache configuration directives. The flaw, …

Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 10, 2026 Hackers are turning everyday software searches into a trap. A sophisticated cryptojacking campaign is actively targeting users who search for popular PC utilities online, luring them into …

Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 10, 2026 Hackers are using fake tax notification emails to trick Windows users into downloading dangerous multi-stage malware that runs entirely in memory, leaving almost no trace behind. The …