BugHunter – Bug Bounty Toolkit Powered by Claude and Free AI Providers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 13, 2026 A new open-source bug bounty hunting toolkit called BugHunter, built on top of Anthropic’s Claude Code and now extended to support free AI providers like Ollama and Groq, is gaining traction in the security research community for …

Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability chain in Splunk Enterprise has been disclosed, enabling unauthenticated attackers to achieve remote code execution (RCE) through a misconfigured PostgreSQL sidecar service. Tracked as CVE-2026-20253, the flaw has a CVSS score of 9.8 and affects Splunk Enterprise …

Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 13, 2026 Anthropic has disabled its two most capable AI models, Fable 5 and Mythos 5, after the U.S. government issued an export control directive late on June 12 ordering the company to block access for any foreign national, …

Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as Fancy Bear, formally tracked as APT28 and attributed to Russia’s military intelligence unit GRU Unit 26165, has …

Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 A newly documented phishing campaign is using a legitimate remote management tool to silently take over victims’ computers, without deploying a single line of traditional malware. Researchers have uncovered an active operation targeting Brazilian organizations, where attackers …

Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly …

Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 A new and dangerous credential-stealing tool called OnyxC2 has emerged in the cybercrime underground, showing just how easy it has become for even low-skilled attackers to run a professional hacking operation. Sold as a complete package for …

400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 A massive supply chain attack targeting the Arch User Repository (AUR) has compromised more than 400 community-maintained packages, with attackers injecting malicious build scripts designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems. The …

Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 A critical vulnerability chain discovered in LangGraph, a popular open-source AI agent framework developed by the creators of LangChain, could allow attackers to gain full server control through remote code execution (RCE). The issue, identified by Check …

Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 12, 2026 Authorities have dismantled a major cryptocurrency laundering service known as “AudiA6,” widely used by ransomware groups and cybercriminal networks to obscure illicit financial flows and cash out stolen digital assets. The international operation targeted what investigators described …