LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials from a wide range of applications. The campaign uses a JScript email attachment as its …

ManageEngine AD360 Integration Flaw Exposes User Identity and Role Information to Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 ManageEngine has disclosed a high-severity vulnerability, tracked as CVE-2026-11374, affecting several of its identity and access management solutions when integrated with AD360. The flaw could allow unauthenticated attackers to predict single sign-on (SSO) tokens, potentially leading to …

Gemini 3.5 Flash Released With Computer Use Capabilities that Build Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Google has officially released Gemini 3.5 Flash with native “computer use” capabilities, marking a significant shift toward autonomous AI agents that can interact directly with digital environments. Announced on June 24, 2026, the update enables developers to …

Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A newly discovered malware campaign has turned Google Chrome into a remote backdoor without breaking any of the browser’s built-in rules. Spotted in June 2026, the attack arrived in Italian-language phishing emails that looked like standard business …

OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, …

Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A newly discovered malware family is making its way onto systems worldwide by hiding inside fake software installers that look completely legitimate. Researchers have identified a campaign where attackers disguise their malicious tools as trusted programs like …

Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Google has released a critical security update for its Chrome browser, pushing the Stable channel to version 149.0.7827.196/197 for Windows and Mac, and 149.0.7827.196 for Linux. The update addresses 18 security vulnerabilities, including four rated Critical and …

Anthropic Accuses Alibaba of ‘Illicitly’ Accessing Its Claude AI Models in Largest Known Distillation Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Anthropic has formally accused Chinese tech and e-commerce giant Alibaba of orchestrating a massive, unauthorized extraction campaign targeting its Claude AI model, marking what the company describes as the largest known distillation attack in its history. In …

Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint security components. This clever camouflage helps it avoid detection, allowing …

Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Threat actors are once again exploiting the trust people place in everyday workplace tools. A newly discovered phishing campaign is using fake Microsoft Teams notifications to trick employees into downloading a remote access tool that gives attackers …