Phishing Emails Push Fake ChatGPT and Gemini iOS Apps To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is targeting iPhone users by impersonating two of the world’s most trusted AI brands — OpenAI’s ChatGPT and Google’s Gemini. The attackers are sending out deceptive …

Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that 90 zero-day vulnerabilities were actively exploited in the wild throughout 2025. While this marks a slight decrease from …

Hackers Can Use Indirect Prompt Injection Allows Adversaries to Manipulate AI Agents with Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence tools are now a core part of everyday workflows — from browsers that summarize web pages to automated agents that help users make decisions online. As these tools …

OpenAI Launches GPT-5.4 With Advanced Reasoning, Coding, and Computer-Use Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GPT-5.4 Launched OpenAI on March 5, 2026, released GPT-5.4, its most capable and efficient frontier model to date, combining advanced reasoning, coding, and agentic workflows into a single unified system. …

PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability A public proof-of-concept (PoC) exploit has been released for CVE-2026-20127, a maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and SD-WAN Manager that has …

Threat Actors Using Fake Claude Code Download to Deploy Infostealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. These deceptive pages …

Suspected DPRK Threat Actors Compromise Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated campaign targeting cryptocurrency organizations has drawn attention from the security community, with evidence pointing to threat actors potentially linked to North Korea’s state-sponsored hacking operations. The attackers moved …

ClickFix Campaign Uses Fake VCs on LinkedIn to Deliver Malware to Crypto and Web3 Professionals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated malware campaign is targeting cryptocurrency and Web3 professionals through a carefully built chain of social engineering, fake venture capital identities, and spoofed video conferencing links. First tracked in …

RedAlert Mobile Espionage Campaign Targets Civilians with Trojanized Rocket Alert App for Surveillance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

War zones have always been hunting grounds for opportunistic attackers, but the RedAlert mobile espionage campaign marks one of the most calculated examples of weaponizing civilian fear. Against the backdrop …

New MongoDB Vulnerability Lets Hackers Crash Any MongoDB Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New MongoDB Vulnerability Crash MongoDB server A high-severity vulnerability, CVE-2026-25611 (CVSS 7.5), has been discovered in MongoDB, allowing unauthenticated attackers to crash exposed servers using minimal bandwidth. According to Cato …