Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has suspended the Windows Hardware Program developer accounts of two critical open-source security projects, VeraCrypt and WireGuard, blocking their ability to sign drivers and push updates to millions of …

New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as DragonBreath has launched a stealthy campaign using a multi-stage malware loader called RoningLoader. The malware targets Chinese-speaking users by disguising itself as trusted software such …

Critical Chrome Vulnerabilities Let Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 147 to the stable channel for Windows, Mac, and Linux, patching a sweeping set of security vulnerabilities — including two critical-severity flaws that could allow remote …

New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign linked to the Silver Fox APT group has been discovered, using a fake Telegram Chinese language pack installer to secretly deliver ValleyRAT — a powerful remote …

Hackers Abuse Legitimate Meta Business Manager Notifications to Deliver Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is actively targeting businesses worldwide by exploiting one of the most trusted tools in digital marketing — Meta’s Business Manager platform. Cybercriminals have found a clever …

Microsoft 365 Network-Level Disruption Affecting Exchange Online, Teams, and Core Suite Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A network-level disruption struck multiple Microsoft 365 services on Wednesday evening, knocking out or degrading access to Exchange Online, Microsoft Teams, and the broader Microsoft 365 suite for users across …

Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilTokens and AMOS redefine modern phishing attacks Two significant threat campaigns from March 2026, one abusing Microsoft’s OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS …

IBM Identity and Verify Access Vulnerabilities Allow Remote Attacker to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security bulletin highlights multiple vulnerabilities in Verify Identity Access and Security Verify Access products. If left unpatched, these widespread security flaws could allow malicious actors to access sensitive …

Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly sophisticated, unpatched zero-day exploit is actively targeting users of Adobe Reader. Detected by the EXPMON threat-hunting system, this malicious PDF file is designed to steal sensitive local data …

Anthropic Unveils Claude Mythos Preview With Powerful Zero-Day Detection Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has introduced Claude Mythos Preview, an advanced language model with extraordinary capabilities for discovering and autonomously exploiting undiscovered zero-day vulnerabilities. To ensure these powerful tools are used defensively, the company …