Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, first analyzed in March 2026, tricks victims into executing a …

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, identified as KB5085516, addressing a critical sign-in bug introduced by the March 2026 Patch Tuesday release. The update carries OS builds 26200.8039 and 26100.8039 and was …

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the platform’s outsourcing partner, Telus. The breach, which reportedly occurred on …

AstraZeneca Data Breach – LAPSUS$ Group Allegedly Claims Access to Internal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking collective LAPSUS$ has resurfaced, allegedly claiming responsibility for a significant data breach involving the multinational pharmaceutical and biotechnology company AstraZeneca. The threat actors are currently attempting to sell a compressed 3GB internal data dump, signaling a potential …

Malicious Script Injection in Trivy Compromise Enables Credential Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Script Injection in Trivy Compromise A sophisticated supply chain attack targeting the official Trivy GitHub Action (aquasecurity/trivy-action) has compromised continuous integration and continuous deployment (CI/CD) pipelines globally. Disclosed in late March 2026, this incident marks the second distinct compromise …

FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FBI, CISA Warn Russian Hackers The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread phishing campaign. The alert warns that Russian Intelligence Services are actively …

Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel update rolls out versions 146.0.7680.153 and 146.0.7680.154 for Windows and …

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score of …

Anthropic Launches Projects Feature for Claude Cowork Desktop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic is expanding Claude Cowork Desktop with a new Projects feature designed to keep files, instructions, and task context organized inside a single workspace. For paid users, the update makes it easier to start from scratch, import an existing chat, …

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 March Update Breaks Teams Microsoft has acknowledged a significant bug introduced by its March 2026 cumulative update that is preventing users from signing into Microsoft Teams Free, OneDrive, and several other Microsoft applications on Windows 11 devices. The …