ClawHub, Cisco, Vercel’s Malicious Skill Detector Bypassed to upload Malicious Skills

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI skill scanners from ClawHub, Cisco, and Vercel’s skills. The platform can be bypassed with minimal effort, allowing malicious skills to be uploaded and distributed through public marketplaces. The findings …

HexStrike AI RED-TEAM With 127 Security Tools and BOAZ Red Team Integration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 A fork of the original HexStrike AI project has been released as HexStrike AI v6.0, an advanced Model Context Protocol (MCP)-based cybersecurity automation framework that merges 127 professional …

Hackers Impersonate Ghidra, dnSpy, and SpiderFoot to Spread Malware via Fake Download Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are creating convincing fake websites that impersonate popular security tools to trick users into downloading malware. Instead of obvious phishing pages, these sites look almost identical …

binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, …

IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A newly discovered malware campaign called IronWorm has been silently targeting software developers through poisoned npm packages, stealing credentials, API keys, and even cryptocurrency wallet recovery phrases. …

Stock Exchange Executive’s Outlook Account Targeted to Exfiltrate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A senior executive at a major global stock exchange had their Microsoft Outlook account silently compromised for five straight months, with attackers carefully siphoning emails in small …

Cybercriminals Shift From Fake Login Pages to Infostealer Malware in Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Phishing attacks have always been one of the most common ways cybercriminals steal personal and business data. But something has quietly changed about how these attacks work. …

Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A sophisticated cybercrime group known as TA4922 is raising alarms across the global security community. The group has been deploying a growing arsenal of malware, including Atlas …

Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new malvertising campaign is exploiting ChatGPT’s popularity by promoting a weaponized fake download site via sponsored search results, delivering malware to both Windows and macOS users. …

Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform …