Hackers Use Recruiter Phishing Emails and Fake Career Pages to Harvest Gmail Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A new phishing campaign is targeting job seekers by posing as recruiters from recognizable brands. The scheme uses fake career pages and worded emails to trick people into handing over Gmail login credentials. What makes this campaign …

Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT. The campaign blends social engineering with legitimate remote support …

OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A newly disclosed vulnerability in the OpenAI Codex desktop application for macOS could allow attackers to exploit indirect prompt injection techniques to exfiltrate sensitive data, according to a recent entry in the GitHub Advisory Database. Tracked as …

Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Iranian-linked hacking group has been caught abusing everyday IT tools to slip malware onto Israeli networks. Researchers have named the group Cavern Manticore, and its latest campaign shows how creative attackers have become at hiding in plain sight. …

Tenda Authentication Backdoor Grants Attackers Full Administrative Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the …

Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems. The issues are tracked …

Windows Device Identifier Used to Arrest Scattered Spider Hacking Group Member

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint filed in the Northern District of Illinois. Peter Stokes, 19, a dual U.S.–Estonian citizen …

Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 7, 2026 A critical security flaw has been discovered in the fast-mcp-telegram package that could allow remote attackers to access sensitive Telegram session data and perform unauthorized actions. The vulnerability, tracked as CVE-2026-52830 , affects all versions up to 0.19.0 and …

Top 10 Best Next-Generation Firewall (NGFW) Solutions in 2026 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Best Next-Generation Firewall (NGFW) Solutions If you’re shortlisting the best next-generation firewall for 2026, Palo Alto Networks’ PA-Series is our top overall pick for its App-ID application control and machine-learning threat prevention, while Fortinet FortiGate delivers the strongest price-to-performance for …

Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A new phishing technique is tricking users into handing over their Microsoft account tokens without a fake website in sight. Attackers are exploiting a legitimate Microsoft authentication feature to steal access to email, files, and chat messages. …