23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or …

Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on …

AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build …

Microsoft Entra Conditional Access Policies Can Be Bypassed Via Nested App Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft Entra Conditional Access Policies (CAPs), a core security control for Azure and Microsoft 365 tenants, were recently found vulnerable to a bypass technique involving Nested App Authentication (NAA), according to research disclosed by NetSPI. CAPs are …

AI-Powered iOS Apps Leaking LLM API Credentials Through Network Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered iOS applications are increasingly leaking large language model (LLM) API credentials through network traffic, exposing developers to large-scale abuse of their LLM accounts and cloud resources. A recent empirical study of 444 free, LLM-enabled iOS apps from the US …

Hackers Use RemotePC RMM and PowerShell Stagers to Deploy Prinz Eugen Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly identified ransomware group is using remote management software and scripted attack tools to compromise organizations and deploy a sophisticated encryption threat called Prinz Eugen. The campaign has claimed victims across multiple countries, with targets ranging …

Microsoft’s New Option Allows Organizations to Block Copilot Access to Office Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft has announced a significant update to its Microsoft 365 security and compliance features, introducing enhanced controls that allow organizations to block Copilot and other connected experiences from analyzing content in Office files. The update is tied …

Microsoft has urged IT Admins to Prepare for Windows 11, Version 26H2 Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft has urged IT administrators to begin preparing for the upcoming Windows 11 version 26H2 update, which is now available for testing through the Windows Insider Program. The release continues Microsoft’s shift toward a predictable, low-disruption servicing …

New Malware Attack Via WhatsApp Attacking Windows System to Enable Remote Access For Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A new and active malware campaign is spreading through WhatsApp, targeting everyday Windows users across more than a dozen countries. The threat uses malicious script files disguised as routine financial documents, tricking people into running harmful code …

GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 GitHub has rolled out a significant security enhancement to GitHub Actions by updating actions/checkout to block unsafe workflows that abuse the pull_request_target event. The pull_request_target trigger is widely known as one of the most misused events because it runs with the base repository’s GITHUB_TOKEN, …