Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections. The discovery links the tool to activity associated with the …

BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead …

Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Cleo Harmony, a widely deployed managed file transfer and integration platform, is putting enterprise networks at risk after security researchers confirmed that remote attackers can …

FBI and CrowdStrike Disrupt 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims worldwide since 2003. The operation spanned the United …

Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI can assist with low-level operational technology exploitation. The …

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used …

Palo Alto Networks Acquires Console to Build AI Agents for Autonomous Security Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has acquired Console, an AI-native platform that will strengthen Cortex by enabling AI-driven security workflows to investigate, prioritize, and remediate threats at machine speed. The acquisition comes …

Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM …

Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Windows PCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are posing as IT technicians on Microsoft Teams and persuading employees to hand over control of their Windows computers. The campaign turns a familiar support conversation into a direct …

Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Silver Fox-linked hackers are using counterfeit software installers to break into Windows systems and weaken the protections meant to stop them. The campaign relies on convincing download pages that copy …