AWS Patches Critical RCE and Escalate Privileges in Research and Engineering Studio

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS) has released an important security bulletin addressing three severe vulnerabilities in its Research and Engineering Studio (RES). These flaws could allow authenticated attackers to execute arbitrary …

WhatsApp Introduces Username Feature for Connecting Without Sharing Phone Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp via username (Source: WABetaInfo) WhatsApp is preparing to roll out a long-anticipated username feature that will allow users to communicate without ever revealing their phone numbers, a significant privacy …

New ClickFix Campaign Uses macOS Script Editor to Deliver Atomic Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered ClickFix campaign is targeting macOS users through a technique that completely bypasses Terminal, using Script Editor to drop the Atomic Stealer infostealer onto compromised systems. This campaign …

Hackers Use ClickFix and Malicious DMG Files to Deliver notnullOSX on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new macOS info-stealer named notnullOSX has surfaced, targeting crypto holders with wallets above $10,000. Written in Go, it uses two parallel attack paths — ClickFix social engineering and malicious …

New STX RAT Uses Hidden Remote Desktop and Infostealer Features to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered remote access trojan called STX RAT has emerged as a serious cybersecurity threat in 2026, combining hidden remote desktop access with credential-stealing features to quietly compromise targeted …

Hackers Use Fake Security Software to Deliver LucidRook Malware in Taiwan Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified malware called LucidRook has been spotted targeting organizations across Taiwan, hiding inside what appears to be legitimate security software. The attackers went out of their way to …

Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Open source developers are facing a growing and sophisticated threat — one that does not rely on complex exploits or hidden vulnerabilities but instead uses something far simpler: trust. A …

CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The agency recently added this flaw, tracked …

GitLab Patches Multiple Vulnerabilities That Enables DoS and Code Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security updates (versions 18.10.3, 18.9.5, and 18.8.9) for its Community Edition (CE) and Enterprise Edition (EE) to address high-severity flaws that enable Denial-of-Service (DoS) and code-injection …

Hackers Claim to Have Stolen 10 Petabytes of Data from China’s Tianjin Supercomputer Center

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are claiming that one of China’s most strategically important computing facilities suffered a massive cyber intrusion, with more than 10 petabytes of sensitive information allegedly taken from a state-run …