Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A faulty URL filtering rule update in Microsoft Exchange Online triggered a widespread false-positive storm beginning February 9, 2026, causing legitimate email messages to be incorrectly flagged as phishing and …

Malware Campaign Delivers Remote Access Backdoor and Fake MetaMask Wallet to Steal Cryptocurrency Funds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors have launched a sophisticated attack campaign targeting IT professionals in cryptocurrency, Web3, and artificial intelligence sectors. The ongoing operation, known as Contagious Interview, deploys remote access …

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ClawHavoc Poisoned OpenClaw’s ClawHub A large-scale supply chain poisoning campaign that targeted OpenClaw’s official marketplace, ClawHub, distributing 1,184 malicious “Skills” designed to steal data and establish backdoor access on compromised …

16 Zero-Day Vulnerabilities in Popular PDF Platforms Enable Code Execution and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PDF Zero-Day Vulnerabilities 16 zero-day vulnerabilities, including critical OS Command Injection, DOM-based XSS, SSRF, and Path Traversal flaws across Apryse WebViewer (formerly PDFTron) and Foxit PDF cloud services, affecting millions …

MetaMask Users Targeted with Phishing Emails Containing Forged Security Report to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is targeting MetaMask users through carefully crafted emails that contain fake security incident reports designed to manipulate victims into compromising their accounts. The attack leverages social …

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paloalto to Acquire Koi Security Palo Alto Networks announced a definitive agreement to acquire Koi Security, a leading innovator in Agentic Endpoint Security, marking a major expansion of its AI‑driven defense …

Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer Use, and 1M Token Context Window

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Sonnet 4.6 Released Anthropic has officially launched Claude Sonnet 4.6, its most capable mid-tier model to date, delivering a comprehensive upgrade across coding, computer use, long-context reasoning, agent planning, …

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Adds Windows Video ActiveX Control RCE Flaw A long-dormant Microsoft Windows vulnerability, CVE-2008-0015, has been added to the Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in …

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Firefox 0-Day RCE A critical Remote Code Execution (RCE) vulnerability in Mozilla Firefox was caused by a single-character typo in the SpiderMonkey JavaScript engine’s WebAssembly garbage collection code, where a …

New Phishing Campaign Targets Booking.com Partners and Customers in Multi-Stage Financial Fraud Scheme

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Booking.com‑themed phishing campaign is abusing trust in travel brands to steal money and sensitive data from both hotels and guests. The scheme can start as a service message, …