Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability in Anthropic’s Claude Chrome Extension exposed over 3 million users to silent prompt-injection attacks, allowing malicious websites to hijack the AI assistant without user interaction. The …

Critical NVIDIA Vulnerabilities Enables RCE and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical March 2026 security updates have been released to fix multiple vulnerabilities across enterprise and AI software systems. The latest advisories highlight severe flaws that could enable attackers to execute arbitrary …

New ClickFix Attack Leverage Windows Run Dialog Box and macOS Terminal to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A social engineering technique called ClickFix has resurfaced with significant force, tricking users on both Windows and macOS into manually executing malicious commands that quietly install malware on their devices. …

Leak Bazaar Turns Stolen Corporate Data Into a Structured Criminal Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “Snow” from SnowTeam posted an advertisement on the Russian-speaking TierOne (T1) cybercrime forum on March 25, 2026, introducing a new criminal service called Leak Bazaar. …

VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and technically advanced rootkit called VoidLink has emerged as a serious threat to Linux systems, blending Loadable Kernel Modules (LKMs) with extended Berkeley Packet Filter (eBPF) programs to …

CISA Warns of Langflow Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the Langflow platform to its Known Exploited Vulnerabilities (KEV) catalog on March 25, 2026. The …

IDrive for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical local privilege escalation vulnerability has been identified in the IDrive Cloud Backup Client for Windows. Tracked as CVE-2026-1995, this local privilege escalation vulnerability affects the IDrive Cloud Backup Client …

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Malware-as-a-Service (MaaS) credential stealer named Torg Grabber has surfaced, showing remarkable development pace over just three months. Starting with simple Telegram-based data exfiltration, it matured into a fully …

Fake Screenshot Lures Used to Infect Web3 Support Staff With Multi-Stage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat group known as APT-Q-27 has been running an active campaign against Web3 customer support teams, using fake screenshot links in live chat windows to silently install a persistent …

Silver Fox Abuses Stolen EV Certificates in AtlasCross RAT Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese-nexus advanced persistent threat group Silver Fox, also tracked as Void Arachne and SwimSnake, is actively targeting Chinese-speaking users and professionals with a sophisticated AtlasCross RAT campaign. Security researcher …