Multiple Vulnerabilities in Firefox 152 Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Mozilla has released Firefox 152 to address multiple high-severity vulnerabilities that could allow remote code execution (RCE) and sandbox escape attacks. The security advisory, published on June 16, 2026, highlights a wide range of flaws affecting core …

Hackers Can Leverage SQL Server 2025 AI Features to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are increasingly finding new ways to abuse legitimate enterprise features, and Microsoft SQL Server 2025’s newly introduced AI capabilities are now raising serious security concerns. SpecterOps researchers have demonstrated that these built-in features can be leveraged for stealthy data …

Hackers Abuse Microsoft Fondue.exe to Side-Load APPWIZ.cpl and Execute Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A newly uncovered attack campaign has brought a rarely scrutinized Windows executable into the spotlight. Threat actors are actively abusing Fondue.exe, a legitimate Microsoft utility built into the Windows operating system, to side-load a malicious control panel file …

Hackers Abuse Legitimate RMM Tools to Maintain Persistent Access and Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Hackers have found a new way to get AI tools to do their dirty work without paying for it. Instead of using their own resources, attackers are hijacking exposed AI model servers and plugging them into automated …

Modern Data Protection Standards: How Organizations Are Strengthening Cybersecurity in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Organizations today operate in an increasingly hostile cyber threat landscape where data protection has become a critical business requirement. While digital transformation delivers greater efficiency and accessibility, it also expands the attack surface that cybercriminals seek to exploit. As a …

F5 Patches NGINX Vulnerability That Enables Code Execution and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 F5 has released an out-of-band security advisory addressing multiple high-severity vulnerabilities in NGINX that could allow attackers to execute arbitrary code and launch denial-of-service (DoS) attacks across affected environments. The advisory, published on June 17, 2026, highlights …

Hackers Abuse PowerShell Commands to Deliver SmartRAT Through Brazilian Bank Phishing Page

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A new cyberattack campaign has emerged, using cleverly crafted phishing pages and PowerShell tricks to deliver a dangerous piece of malware called SmartRAT. The attack targets Brazilian banking customers and combines social engineering with AI-generated web pages …

Evilginx AiTM Attack Captures Microsoft Credentials, MFA Tokens, and Authenticated Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A growing wave of targeted phishing attacks is putting Microsoft users at serious risk, and the tool behind it is more sophisticated than most people realize. Security researchers have documented how Evilginx, an adversary-in-the-middle framework, is being …

PoC Exploit Released for HTTP/2 Bomb Remote DoS Vulnerability in Apache HTTP Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical Denial of Service vulnerability in Apache HTTP Server, tracked as CVE-2026-49975, dubbed the “HTTP/2 Bomb.” The flaw allows remote attackers to exhaust server memory and disrupt services without authentication, …

Hackers Abuse PowerShell, VBScript, and BAT Files to Deliver Xctdoor Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks is targeting corporate employees through files that look exactly like legitimate job documents. Hackers are distributing malicious LNK files disguised as resumes, and the moment a victim opens one, the infection quietly begins. The attack …