PoC Exploit Released for libssh2 Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A public proof-of-concept (PoC) exploit for the critical libssh2 remote code execution vulnerability tracked as CVE-2026-55200 is now available, significantly increasing the risk of real‑world attacks against unpatched systems. The flaw affects libssh2 versions up to and …

Browser-in-the-Browser Kit Uses Fake Software Errors to Deliver Malware Installers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified attack campaign is using a sophisticated Browser-in-the-Browser (BitB) kit to trick users into downloading malware disguised as legitimate software installers. The technique combines convincing fake browser pop-ups with fabricated error messages to manipulate victims …

GhostShell Malware Uses mTLS Implant and Telegram Dead-Drop to Target Ukrainian Drone Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified malware cluster known as GhostShell has been found actively targeting Ukraine’s drone operations and its broader defense supply chain. The campaign uses a sophisticated combination of techniques, including a mutual TLS implant and a …

Red-Team AI Tool Vulnerabilities Let Attackers Exfiltrate API Keys and Compromise Operators’ Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A first-of-its-kind security analysis of 12 widely deployed agentic offensive-security tools reveals critical architectural flaws that allow adversaries to steal LLM API keys, establish persistent footholds, and achieve full host compromise even inside sandboxed containers. Security researchers …

Hackers Exploit Unpatched SharePoint Servers to Deploy Ransomware and Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Unpatched on-premises SharePoint servers have become a prime target for sophisticated threat actors using known security flaws to break in, plant ransomware, and leave behind hidden backdoors. These are not opportunistic smash-and-grab operations. They are calculated, multi-stage …

Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A malicious AI “skill” created as part of a controlled security experiment has exposed critical weaknesses in modern AI agent ecosystems, successfully bypassing security scanners and compromising more than 26,000 agents across individual and enterprise environments. According …

Claude Fable 5 Wrote Windows Kernel Code in Rust in 38 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Anthropic’s Claude Fable 5 generated a complete, bootable NT-compatible Windows kernel written in Rust called ntoskrnl-rs from an empty directory in just 38 minutes of active model work, raising profound questions about AI-authored trust and the future …

GTA 6 Scam Websites Use AI-Generated Images and Fake Download Buttons to Lure Gamers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of scam websites is targeting gamers worldwide, using the massive hype around Grand Theft Auto VI to trick people into handing over their money. These fake pages promise something millions of players desperately want: early access to …

FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A large-scale, ongoing credential-harvesting campaign dubbed “FortiBleed” has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since at least February 2026. The campaign came to light after …

How Attackers Exploit Privileged Access and How to Lock Them Out 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every major breach you read about has a quiet middle chapter that rarely makes the headline. The headline is the ransom note or the leaked customer database. The middle chapter the part that actually decided the outcome is almost always the same: an attacker found a …