OpenClaw Advisory Surge Exposes Gap Between GitHub and CVE Vulnerability Tracking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw, a self-hosted AI agent, rose to become GitHub’s most-starred repository weeks after its launch, drawing a large developer community and immediate researcher attention. Nobody anticipated this growth would soon become an unexpected stress test for the global vulnerability tracking …

Anthropic Sued the U.S. Government for Labelling Claude as ‘Supply Chain Risk’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic Sued the U.S. Government Artificial intelligence leader Anthropic has filed an unprecedented lawsuit against the United States government after being designated a “supply chain risk”. The legal action, filed in a California federal court on Monday, targets the executive …

Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache ZooKeeper Vulnerability Two “Important” severity vulnerabilities have been disclosed in Apache ZooKeeper, a widely used service for configuration management and naming in distributed applications, making timely security updates critical. These newly discovered flaws could allow attackers to access sensitive …

Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered phishing campaign is actively targeting enterprise users by disguising malware as widely used workplace applications, including Microsoft Teams, Zoom, and Adobe Acrobat Reader. What makes this threat stand out is that the malicious files carry legitimate-looking digital …

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese-linked advanced persistent threat group known as Camaro Dragon launched a targeted cyberespionage campaign against entities in Qatar just one day after the outbreak of new hostilities in the Middle East on March 1, 2026. The group used war-themed …

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign targeting software developers has surfaced, with a rogue npm package posing as a trusted developer tool to silently drain credentials, crypto wallets, SSH keys, browser sessions, and even iMessage conversations. The package, published under the name @openclaw-ai/openclawai, …

ScamAgent- AI Agent Built by Researchers that Run Fully Autonomous Scam Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ScamAgent is an autonomous, multi-turn AI framework developed by researcher Sanket Badhe at Rutgers University that demonstrates how large language models (LLMs) can be weaponized to conduct fully automated scam calls. By integrating goal-driven planning, contextual memory, and real-time text-to-speech …

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers Attack Over Microsoft Teams A social-engineering campaign abusing Microsoft Teams and Windows Quick Assist is evolving again, with BlueVoyant warning that the attackers are now deploying a newly identified malware family called A0Backdoor after convincing employees to hand over …

Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A convincing fake website posing as the popular Mac utility CleanMyMac is actively pushing dangerous macOS malware called SHub Stealer onto unsuspecting users. The site, hosted at cleanmymacos[.]org, has no connection to the real CleanMyMac software or its developers, MacPaw. …

BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new data-stealing malware called BoryptGrab has been quietly spreading across Windows systems through a network of fake GitHub repositories, tricking users into downloading what appear to be popular free software tools. The campaign, which has been active since at …