MCP Servers can be Exploited to Execute Arbitrary Code and Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Model Context Protocol (MCP) emerged as a breakthrough standard in November 2024, designed by Anthropic to seamlessly connect AI assistants with external systems and data sources. This innovation allows …

OpenAI Launches EVMbench to Detect, Patch, and Exploit Vulnerabilities in Blockchain Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI EVMbench OpenAI, in collaboration with crypto investment firm Paradigm, has introduced EVMbench, a new benchmark designed to evaluate the ability of AI agents to detect, patch, and exploit high-severity …

Guardian AI-Penetration Testing Tool Connects Gemini, GPT-4 with 19 Security Tools Including Nmap

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Guardian AI-Penetration Testing Tool A new open-source framework is reshaping how security professionals approach penetration testing by placing multiple large language models directly at the helm of automated security assessments. …

Hackers Can Leverage Grok and Copilot for Stealthy Malware Communication and Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Grok and Copilot for Malware Communication A novel attack technique that repurposes mainstream AI assistants, specifically xAI’s Grok and Microsoft Copilot, as covert command-and-control (C2) relays, enabling attackers to tunnel …

Cryptocurrency Scams Target Asia, Combining Malvertising and Pig Butchering with Losses Up to ¥10 Million

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cryptocurrency scam campaign is currently targeting users across Asia, with a heavy and specific focus on Japan. This operation uniquely combines two distinct fraud models into a single, …

Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in The Wild Targeting Corporate Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have emerged as a major threat to enterprise networks, with active exploitation campaigns targeting corporate infrastructure across multiple countries. The …

Fake CAPTCHA (ClickFix) Attack Chain Leads to Enterprise‑Wide Malware Infection in Organisations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack campaign leveraging “ClickFix” social engineering has emerged, posing a severe threat to enterprise networks globally. These massive campaigns, which trick users into executing malicious code under the …

ClickFix Abuses Legitimate Homebrew Workflow to Deploy Cuckoo Stealer on macOS for Credential Harvesting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign is targeting macOS developers through fake Homebrew installation pages that deploy Cuckoo Stealer, a comprehensive credential-harvesting malware. The attack leverages the ClickFix technique, which tricks …

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security flaw in Microsoft 365 Copilot is causing the AI assistant to incorrectly summarize email messages protected by confidentiality sensitivity labels, bypassing configured Data Loss Prevention (DLP) policies dxposing …

Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A faulty URL filtering rule update in Microsoft Exchange Online triggered a widespread false-positive storm beginning February 9, 2026, causing legitimate email messages to be incorrectly flagged as phishing and …