TP-Link Router Vulnerability Allows Attackers to Execute Arbitrary System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed high-severity vulnerability in TP-Link routers could allow attackers to execute arbitrary system commands and fully compromise affected devices. Tracked as CVE-2026-5509, the flaw affects Archer BE450 v1 and Archer BE7200 v1 models. It has been assigned a …

Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical supply chain vulnerability in Claude Code’s GitHub Actions that could allow attackers to compromise any repository using Anthropic’s official CI/CD workflow, including Anthropic’s own infrastructure. The vulnerability, discovered by security researcher RyotaK of GMO Flatt …

Hackers Deploy AZUREVEIL Adaptix C2 Agent via Spearphishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly identified spearphishing campaign has been quietly targeting government officials, researchers, and technology workers in the Czech Republic and Taiwan. Threat researchers traced the operation to a China-linked threat actor, with the earliest known sample surfacing …

PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly analyzed remote access trojan called PHANTOMPULSE has drawn serious attention for its advanced approach to compromising Windows systems. The malware is the final-stage payload in a broader attack chain known as REF6598, a threat cluster …

Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore and also tracked as UNC1549 and Smoke Sandstorm, has a …

Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The flaw, tracked as CVE-2025-48595, was highlighted in the June 2026 …

Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive enterprise infrastructure. The issue, tracked as CVE-2026-4387, was discovered by …

Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot to hand over access. Over the weekend, high-value “OG” Instagram …

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s …

IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 1, 2026 IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The flaw, tracked as CVE-2026-8633, affects environments that use the optional …