Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Joomla Novarain/Tassos Framework Vulnerabilities Websites running the Novarain/Tassos Framework are vulnerable to critical security flaws that allow unauthenticated file read, file deletion, and SQL injection attacks, potentially leading to remote …

Hackers Can Weaponize ‘Summarize with AI’ Buttons to Inject Memory Prompts Into AI Recommendations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security threat has emerged targeting users of AI assistants through a technique called AI Recommendation Poisoning. Companies and threat actors embed hidden instructions in seemingly harmless “Summarize with …

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign targeting macOS users has emerged, deploying a dangerous stealer malware through an evolved version of the ClickFix attack technique. Named “Matryoshka” after the Russian nesting …

LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new version of LockBit ransomware has emerged, targeting multiple operating systems and threatening businesses worldwide. LockBit 5.0, released in September 2025, represents a major upgrade to one of …

New ZeroDayRAT Attacking Android and iOS For Real-Time Surveillance and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ZeroDayRAT is a new mobile spyware platform sold openly through Telegram, with activity first observed on February 2, 2026. It targets Android (5–16) and iOS (up to 26), giving attackers …

Critical Airleader Vulnerability Exposes Systems to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Airleader Vulnerability A newly disclosed vulnerability in an industrial control system (ICS) monitoring solution has raised concerns across multiple critical infrastructure sectors. Published by CISA under advisory code ICSA-26-043-10, the flaw …

OpenClaw Founder Peter Steinberger Officially Joins OpenAI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw Founder Peter Steinberger Joins OpenAI OpenClaw founder Peter Steinberger has officially joined OpenAI, marking a notable collaboration between open-source innovation and one of the world’s leading AI research organizations. According to Steinberger’s …

Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The state-sponsored threat group Lotus Blossom successfully breached the official hosting infrastructure of Notepad++ between June and December 2025, targeting users across government agencies, telecommunications companies and critical infrastructure sectors. …

CISA Warns of ZLAN ICS Devices Vulnerabilities Allows Complete Device Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ZLAN ICS Devices Vulnerabilities An alert regarding two critical vulnerabilities found in ZLAN Information Technology Co.’s ZLAN5143D industrial communication device. According to the advisory (ICSA-26-041-02), successful exploitation could allow attackers …

Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BeyondTrust Vulnerability Exploit A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to …