Bing Search for ‘ManageEngine OpManager’ Delivers Akira Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A simple Bing search for a popular IT tool turned into a full-scale ransomware attack. Threat actors abused search engine optimization (SEO) poisoning to push a fake download link into Bing search results, tricking IT administrators into …

Hackers Use SystemBC Malware to Hide C2 Traffic and Maintain Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A cyberattack tool that quietly turns victim computers into tunnels for criminal traffic has been gaining ground across enterprise networks. Security researchers have linked it to some of the most destructive ransomware operations in recent years. Known …

GitHub Advisory Database Hits Record Volume as Vulnerability Reports Surpass Review Capacity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitHub’s Advisory Database reached an all-time high in May 2026, publishing 1,560 reviewed security advisories, more than five times its typical monthly output. Despite this milestone, the platform still struggled to keep pace with a rapidly expanding volume of vulnerability …

PoC Released for NTLM Reflection Bypass Flaw that Enables SYSTEM Access on Windows Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A working proof-of-concept (PoC) exploit has been released for a new NTLM reflection bypass flaw that enables SYSTEM-level access on Windows Server 2025, raising fresh concerns about the resilience of Microsoft’s authentication hardening. The vulnerability, tracked as …

SimpleHelp Authentication Bypass Vulnerability Exploited in the Wild to Deploy TaskWeaver Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software is being actively exploited in the wild. This enables attackers to deploy advanced malware, including a newly identified loader, TaskWeaver, and an information-stealing tool, …

Mustang Panda Abuses Zoho WorkDrive for Command-and-Control and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A China-aligned cyber espionage group known as Mustang Panda has been caught running two simultaneous attack campaigns against Indian government and energy targets, using a trusted cloud storage service as its hidden command center. The group deployed …

X Launches Hosted MCP Servers to Connect Cursor, Claude, and Other AI Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 X (formerly Twitter) has officially launched hosted Model Context Protocol (MCP) servers, enabling AI development tools such as Grok Build, Cursor, and Claude Desktop to seamlessly connect with the platform’s API and documentation. Announced on Tuesday, the …

New Windows Backdoor Mistic Enables In-Memory Code Execution and Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 A newly identified Windows backdoor called Mistic has been quietly making its way through enterprise networks since April 2026, giving attackers persistent, low-profile access that is extremely difficult to detect. The malware has been spotted targeting organizations …

Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers …

Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 30, 2026 Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The …