Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks is putting financial institutions on high alert, as threat actors ramp up the use of PXA Stealer — a powerful information-stealing malware — against organizations …

Telnyx PyPI Package With 742,000 downloads Compromised in TeamPCP Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The official Telnyx Python SDK on PyPI was compromised this morning as part of an escalating, weeks-long supply chain campaign orchestrated by the threat actor group TeamPCP. Malicious versions 4.87.1 …

Red Hat Warns of Malware Code Embedded in Popular Linux Tool Allow Unauthorized Access to Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat has issued a critical security warning regarding malicious code discovered in recent versions of the “xz” compression tools and libraries. Tracked as CVE-2024-3094, this highly sophisticated supply chain …

Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloud Software Group has issued a critical security bulletin detailing two newly discovered vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances. These flaws, tracked as CVE-2026-3055 and CVE-2026-4368, could …

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new macOS malware that was undocumented previously, is quietly tricking users through fake Cloudflare human verification pages. Called Infiniti Stealer, this threat uses a well-known social engineering trick called …

New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly analyzed local privilege escalation vulnerability in the Windows Error Reporting (WER) service allows attackers to easily gain full SYSTEM access. The flaw, tracked as CVE-2026-20817, was considered so …

ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) has released a critical security advisory warning network administrators of a high-severity vulnerability affecting the Kea DHCP server. Tracked as CVE-2026-3608, this flaw allows unauthenticated …

Anthropic’s Leaked Drafts Expose Powerful New AI Model “Claude Mythos”

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has inadvertently exposed highly sensitive internal documents, revealing the existence of a powerful, unreleased AI model dubbed “Claude Mythos.” The leak, which stems from an unsecured and publicly searchable …

Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability in Anthropic’s Claude Chrome Extension exposed over 3 million users to silent prompt-injection attacks, allowing malicious websites to hijack the AI assistant without user interaction. The …

Critical NVIDIA Vulnerabilities Enables RCE and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical March 2026 security updates have been released to fix multiple vulnerabilities across enterprise and AI software systems. The latest advisories highlight severe flaws that could enable attackers to execute arbitrary …