New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A new Linux kernel local privilege escalation vulnerability, dubbed “DirtyClone” (CVE-2026-43503), that allows unprivileged local users to gain full root access by manipulating cloned network packets through the XFRM/IPsec subsystem, all without leaving a trace in kernel …

Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A high-severity vulnerability in the Amazon Q Developer Extension for Visual Studio Code (VS Code), Amazon’s AI-powered coding assistant. Tracked as CVE-2026-12957 and CVE-2026-12958 and disclosed by Wiz Research, the flaws allowed attackers to achieve arbitrary code …

New Linux pedit COW Exploit Allows Attackers to Gain System Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed Linux kernel vulnerability combining a Copy-on-Write (COW) page-cache corruption flaw with the net/sched subsystem’s act_pedit component is enabling unprivileged local attackers to escalate privileges to full root access on several major Linux distributions. The exploit, dubbed packet_edit_meme, …

New Bluekit Phishing-as-a-Service Bypasses MFA to Steal Microsoft Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Phishing-as-a-Service (PhaaS) platform called Bluekit has been confirmed operational at scale, with cybersecurity firm Netcraft detecting approximately 70 live hostnames in a single week. First documented by Varonis Threat Labs as an emerging tool still in development, Bluekit …

Hackers Exploit Weak Credentials and Internet-Facing PLCs to Breach Water Utilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Water utilities across the United States and Europe are under growing pressure as hackers continue to find easy ways in. Nation-state actors and affiliated groups have been quietly exploiting internet-facing control systems and weak login credentials to …

New GIFTEDCROOK Chain Abuses WinRAR ADS and Reflective Loading to Steal Browser Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A newly documented attack chain tied to threat actor group UAC-0226 is putting Windows users at serious risk. The campaign uses booby-trapped WinRAR archives, hidden file streams, and a sophisticated memory-loading technique to deliver GIFTEDCROOK, a stealer …

Hackers Leveraged Shopify Oder-Tracking App Shop to Push Fake Invoices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Hackers are no longer waiting in your inbox. A newly identified scam technique places fake invoices directly inside shopping app order histories, making them feel more credible than a typical phishing email. Researchers have observed fraudulent receipts …

Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the python.org release management API could have allowed attackers to impersonate administrators, potentially redirecting millions of users to malicious download URLs. The flaw, responsibly disclosed on February 23, 2026, by Splitline Ng of the …

KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered infostealer called KuinaExtractor has been quietly evolving for over six months, posing a serious and growing threat to users across multiple platforms. Written in the Rust programming language, the malware targets browser data, cryptocurrency wallets, and credentials …

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, active since at least March 2022, spent much of 2025 …