OpenClaw Advisory Surge Exposes Gap Between GitHub and CVE Vulnerability Tracking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw, a self-hosted AI agent, rose to become GitHub’s most-starred repository weeks after its launch, drawing a large developer community and immediate researcher attention. Nobody anticipated this growth would soon …

Anthropic Sued the U.S. Government for Labelling Claude as ‘Supply Chain Risk’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic Sued the U.S. Government Artificial intelligence leader Anthropic has filed an unprecedented lawsuit against the United States government after being designated a “supply chain risk”. The legal action, filed …

Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache ZooKeeper Vulnerability Two “Important” severity vulnerabilities have been disclosed in Apache ZooKeeper, a widely used service for configuration management and naming in distributed applications, making timely security updates critical. …

Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered phishing campaign is actively targeting enterprise users by disguising malware as widely used workplace applications, including Microsoft Teams, Zoom, and Adobe Acrobat Reader. What makes this threat …

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese-linked advanced persistent threat group known as Camaro Dragon launched a targeted cyberespionage campaign against entities in Qatar just one day after the outbreak of new hostilities in the …

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign targeting software developers has surfaced, with a rogue npm package posing as a trusted developer tool to silently drain credentials, crypto wallets, SSH keys, browser sessions, …

ScamAgent- AI Agent Built by Researchers that Run Fully Autonomous Scam Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ScamAgent is an autonomous, multi-turn AI framework developed by researcher Sanket Badhe at Rutgers University that demonstrates how large language models (LLMs) can be weaponized to conduct fully automated scam …

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers Attack Over Microsoft Teams A social-engineering campaign abusing Microsoft Teams and Windows Quick Assist is evolving again, with BlueVoyant warning that the attackers are now deploying a newly identified …

Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A convincing fake website posing as the popular Mac utility CleanMyMac is actively pushing dangerous macOS malware called SHub Stealer onto unsuspecting users. The site, hosted at cleanmymacos[.]org, has no …

BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new data-stealing malware called BoryptGrab has been quietly spreading across Windows systems through a network of fake GitHub repositories, tricking users into downloading what appear to be popular free …