VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, the attacker’s own decryptor may not fully restore their files. …

Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and …

Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 Let’s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without bloating TLS handshakes or breaking the web’s performance expectations. Traditional …

Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw …

ClawHub, Cisco, Vercel’s Malicious Skill Detector Bypassed to upload Malicious Skills

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI skill scanners from ClawHub, Cisco, and Vercel’s skills. The platform can be bypassed with minimal effort, allowing malicious skills to be uploaded and distributed through public marketplaces. The findings highlight a growing supply chain risk in agent ecosystems, where …

HexStrike AI RED-TEAM With 127 Security Tools and BOAZ Red Team Integration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 5, 2026 A fork of the original HexStrike AI project has been released as HexStrike AI v6.0, an advanced Model Context Protocol (MCP)-based cybersecurity automation framework that merges 127 professional security tools with BOAZ, a multi-layered, EDR/AV payload evasion engine …

Hackers Impersonate Ghidra, dnSpy, and SpiderFoot to Spread Malware via Fake Download Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 Hackers are creating convincing fake websites that impersonate popular security tools to trick users into downloading malware. Instead of obvious phishing pages, these sites look almost identical to real project portals, complete with professional designs and links …

binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to …

IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A newly discovered malware campaign called IronWorm has been silently targeting software developers through poisoned npm packages, stealing credentials, API keys, and even cryptocurrency wallet recovery phrases. The attack is built to spread itself through trusted developer …

Stock Exchange Executive’s Outlook Account Targeted to Exfiltrate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 4, 2026 A senior executive at a major global stock exchange had their Microsoft Outlook account silently compromised for five straight months, with attackers carefully siphoning emails in small batches to avoid detection. The intrusion ran from October 2025 …