Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for …

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS …

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting …

Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those …

CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that …

New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 OpenAI has released ChatGPT Lockdown Mode, a new security feature designed to limit outbound network access and reduce the risk of data exfiltration from prompt-injection attacks. The …

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are …

OWASP CVE Lite CLI – New Tool to Scan for Vulnerabilities in Your Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 CVE Lite CLI is a free, open-source vulnerability scanner officially recognized as an OWASP Incubator Project, designed to bring dependency security directly into developers’ terminals rather than …

Anthropic’s Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated]

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 Anthropic’s Claude platform suffered a significant service disruption on June 5, 2026, with elevated error rates impacting multiple frontier AI models and key services, including claude.ai, Claude …