AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A stealthy campaign is turning trusted remote access software into a weapon against everyday users and businesses. Attackers have hidden the AsyncRAT trojan inside fake software installers, letting it slip past basic security checks. The campaign relies …

Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly uncovered phishing panel called ARToken is giving cybercriminals an easy way to steal Microsoft 365 login sessions without ever touching a password. The tool works by abusing a legitimate Microsoft sign in feature meant for …

AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 AsyncRAT is back in the headlines, and the attackers behind it have found a clever way to hide in plain sight. Instead of relying on suspicious servers, they use Dropbox links and TryCloudflare tunnels, both trusted services …

Ousaban Malware Uses Phishing PDFs and VBS Downloader to Target Iberian Banking Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly documented campaign is quietly hijacking online banking sessions across Spain and Portugal, and it starts with something as ordinary as a broken PDF file. The malware behind it, known as Ousaban, has resurfaced with a …

Claude Cowork’s Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A vulnerability chain in Anthropic’s Claude Cowork allows an attacker with local code execution to escalate privileges and run arbitrary commands as root inside the product’s isolated Linux sandbox, bypassing every layer of defense Anthropic built into …

CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a coordinated scanning-and-exploitation campaign across three separate sensor deployments. Within 24 …

DHS Confirms Breach of Information-Sharing Network Platform HSIN

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform relied upon by federal, state, local, tribal, territorial, international, and private-sector partners to coordinate emergency response …

ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd through the platform’s file download mechanism. According to Security researcher …

900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerability in the platform, putting mission‑critical ERP environments at immediate risk of compromise. …

Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers have uncovered a campaign that abuses the popular VLC media player to …