Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to …

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, …

DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo has rolled out native YouTube ad blocking across its browser applications, automatically stripping pre-roll and mid-roll video ads without requiring users to install third-party extensions. The feature works across YouTube and other video platforms, marking a significant shift in …

OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 Melbourne, Florida, United States, July 8th, 2026, CyberNewswire OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies …

Claude Cowork Allow Users to Remotely Handle Your AI Sessions From Phone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 Claude has introduced a major update to its Cowork feature, enabling users to remotely manage and continue AI-driven sessions across mobile and web platforms. The rollout marks a shift toward persistent AI task execution, allowing users to …

Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to …

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying …

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proof-of-concept (PoC) exploit code and deep technical details have now been released for CVE-2025-53770, a critical remote code execution (RCE) vulnerability in on‑premises Microsoft SharePoint Server. This disclosure raises the risk of rapid weaponization and mass exploitation against unpatched SharePoint …

First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A full-chain exploit dubbed “IonStack” demonstrates how a single malicious URL click can hand attackers complete control over an Android device. The proof-of-concept by Nebula Security, described as the world’s first public Android 17 root demo, chains …

CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Adobe ColdFusion vulnerability, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in real-world attacks. The …