PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes by luring them to a malicious webpage. Tracked as CVE-2026-33829, the flaw resides …

iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers, working in partnership with OpenAI, have uncovered a fascinating and severe vulnerability in iTerm2, a widely used macOS terminal emulator. According to Califio, the flaw abuses the application’s SSH integration feature, allowing attackers to turn seemingly harmless text …

Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in Anthropic’s Model Context Protocol (MCP) exposes over 150 million downloads to potential compromise. The vulnerability could enable full system takeover across up to 200,000 servers. The OX Security Research team identified the flaw as a fundamental design …

Gh0st RAT and CloverPlus Adware Delivered Together in New Dual-Payload Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified malware campaign is raising serious concerns across the cybersecurity community by delivering two very different threats at the same time. Attackers are now using a single, obfuscated loader to push both Gh0st Remote Access Trojan (RAT) and …

Hackers Use AppDomain Hijacking to Turn Trusted Intel Utility Into Malware Launcher

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a highly sophisticated attack campaign that weaponizes a legitimate, digitally signed Intel utility to secretly deploy malware, all without touching a single line of the original program’s code. The campaign, dubbed Operation PhantomCLR, represents a serious evolution …

North Korea-Linked UNC1069 Uses Fake Zoom and Teams Meetings to Hack Crypto Professionals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean threat group known as UNC1069 has been running a sophisticated campaign that tricks cryptocurrency and Web3 professionals into joining fake online meetings, only to infect their computers with malware designed to steal digital assets. The group pretends …

Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran’s Ministry of Intelligence and Security (MOIS) has been running a long and carefully organized cyber campaign using three separate hacker identities. These identities, known as Homeland Justice, Karma/KarmaBelow80, and Handala, were widely believed to be independent hacktivist groups. However, …

Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical Broken Object Level Authorization (BOLA) vulnerability in Lovable, the popular AI-powered app builder platform, is reportedly allowing unauthorized users to access sensitive project data, including source code, database credentials, AI chat histories, and real customer information from thousands …

Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor to steal credentials and deliver ransomware without triggering endpoint security alerts. This alarming shift in attacker behavior highlights how freely available, trusted software …

Hackers Use MiningDropper to Deliver Infostealers, RATs, and Banking Malware on Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fast growing Android malware campaign is using a framework called MiningDropper to push far more dangerous threats onto phones disguised as normal apps. Researchers describe it as a multi stage delivery system that can lead to infostealers, remote access …