RedLine C2 Pivot Reveals Seven Fraudulent Domains Used in Maritime Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A single leaked command and control server ended up unraveling an entire phishing operation aimed at the maritime shipping world. What started as a routine look at RedLine Stealer traffic turned into the discovery of seven fake …

15-Year-Old Arrested Over Bandai Channel Cyberattack Using a ChatGPT-Assisted Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 Japanese police have arrested a 15-year-old high school student from Tokorozawa City, Saitama Prefecture, on suspicion of fraudulent obstruction of business after he allegedly used a ChatGPT-assisted program to launch a sustained cyberattack against Bandai Channel, a …

Agent Skill Malware Targets Claude Code and OpenAI Codex With Scanner-Evasion Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A new class of malicious software is quietly slipping past the security tools meant to protect popular AI coding assistants. Researchers have found that malware hidden inside “agent skills,” small add-on packages used by tools like Claude …

Gaslight macOS Malware Uses Prompt Injection to Evade AI Security Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A fresh piece of Mac malware has surfaced, and it comes with a twist that security teams have not seen before. Written in Rust and tied to North Korean hacking groups, this malware does not just steal …

Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A newly disclosed vulnerability in Opera GX allowed attackers to silently exfiltrate sensitive user data with no interaction required, simply by luring victims to a malicious website. The issue, documented in recent research titled “One trigram at …

New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. …

Hackers Abuse OpenAI Org Invites to Harvest Sensitive Prompts and API Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 6, 2026 Hackers are actively abusing OpenAI’s organization invitation feature to launch a new form of “poisoned tenant” attack, allowing them to harvest sensitive prompts, API activity, and potentially corporate data from unsuspecting users. According to research disclosed by …

SSH Honeypots Miss Most Post-Login Attacks by Focusing on Interactive Shells

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSH honeypots, widely used in cyber defense, may miss most real-world post-login attacker activity, according to new research that challenges long-standing assumptions in deception technology. A recent study titled “Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots” by researchers …

Parrot 7.3 Released With Optimized Packages and Updated Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Parrot Security has released Parrot OS 7.3, introducing significant system-level optimizations, updated security tools, and a redesigned application management experience to improve performance and usability for security professionals. The update arrives just months after the previous release, with developers focusing …

T3MP3ST Security Framework With 35 Tools, Turns AI Coding Agents Into 0-Day Bug Hunters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 5, 2026 A newly released open-source security framework called T3MP3ST is turning general-purpose AI coding agents like Claude Code, OpenAI’s Codex, and Hermes into autonomous red-teaming operators without requiring new API keys, cloud infrastructure, or additional billing. Built by …