OpenClaw 0-Click Vulnerability Allows Malicious Websites to Hijack Developer AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-interaction vulnerability in OpenClaw, one of the fastest-growing open-source AI agent frameworks in history, has been discovered by Oasis Security researchers, allowing any malicious website to silently seize …

Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Infoblox Threat Intel have uncovered a highly sophisticated phishing campaign that exploits the foundational plumbing of the internet to bypass enterprise security controls. In a novel evasion …

Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers Abuse Windows File Explorer WebDAV Cybercriminals are increasingly abusing a legacy feature within Windows File Explorer to distribute malware, bypassing traditional web browser security and endpoint detection controls. According …

Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Metasploit Adds New Modules Targeting Linux RC4 The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new …

Trump Bans Anthropic AI in Federal Agencies — Pentagon Flags Claude as Security Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. government has taken unprecedented action against domestic AI firm Anthropic, directing all federal agencies to immediately stop using its AI model Claude and officially designating the company a …

Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

For years, taking down a botnet meant finding its command-and-control (C2) server, seizing the domain, and watching the network go dark. Law enforcement used this method to dismantle major operations …

Vshell Gains Traction Among Threat Actors as an Alternative to Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Go-based command-and-control (C2) framework originally marketed within Chinese-speaking offensive security communities has been quietly expanding its reach, drawing growing attention from threat actors seeking flexible and cost-effective alternatives to …

Critical Trend Micro Apex One Vulnerabilities Allows Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro Apex One Vulnerabilities Trend Micro has released fixes for multiple Apex One vulnerabilities, ranging from High to Critical severity, including management console issues that can lead to remote code execution …

Malicious Go Crypto Module Steals Passwords and Deploy Rekoobe Backdoor in Developer Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Go Crypto Module Steals Passwords and Deploys Rekoobe Backdoor in Developer Environments A newly discovered supply chain attack is putting Go developers at serious risk. A threat actor published …