Debian 13 Released With Security Updates, Bug Fixes and Driver Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 The Debian Project has released Debian 13.6, the latest maintenance update for Debian 13 “trixie.” The point release focuses on security corrections and fixes for serious software issues across the operating system’s package collection. Debian 13.6 is …

Hackers Using Vibe-Coded Generated PowerShell Script to Enumerate Active Directory Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Threat actors have started weaponizing AI-generated PowerShell code to map Active Directory (AD) environments, marking a notable shift from off-the-shelf hacking tools to bespoke, “vibe-coded” malware. Security researchers at Huntress recovered and reconstructed one such script, dubbed …

CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has added two high-risk Joomla extension flaws to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities allow unrestricted file uploads, a weakness that attackers can abuse to upload malicious files …

iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts …

Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked …

VEXAIoT Multi-Agent System Automates IoT Reconnaissance and Exploit Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Security researchers have introduced VEXAIoT, an AI-powered multi-agent framework designed to automate vulnerability discovery and exploit execution against Internet of Things environments. The research shows how large language model agents can coordinate reconnaissance, attack planning, command generation, …

Armored Likho APT Uses AI-Generated Loaders to Deploy BusySnake Stealer Against Government Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer. The operation has targeted government agencies and electrical power organizations, putting sensitive public-sector data and essential services at risk. …

Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 A supply chain attack on the jscrambler npm package, a JavaScript code-protection tool with over 15,800 weekly downloads, involved malicious versions that silently deployed native malware on Linux, macOS, and Windows systems. Socket Research Team detected the …

Anthropic Extends Claude Fable 5 Access From July 12 to July 19

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 Anthropic has extended promotional access to Claude Fable 5 until July 19, 2026, giving eligible paid subscribers more time to use the company’s newest AI model at no additional charge. The offer was previously scheduled to end …

Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 13, 2026 A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package that appears connected to a real seminar. The attackers used …