Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting developers surfaced on March 2, 2026, when unauthorized code was found inside two versions of the Aqua Trivy VS Code extension on the OpenVSX registry. The compromised versions — 1.8.12 and 1.8.13 — were uploaded …

Hackers Leveraged CyberStrikeAI Tool to Breach Fortinet FortiGate Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CyberStrikeAI Tool Breach FortiGate Devices A new artificial intelligence (AI) offensive security tool called CyberStrikeAI, which is being actively leveraged by threat actors to target edge devices, particularly Fortinet FortiGate appliances. This open-source platform, developed by a China-based individual with …

Android Security Update – Patch for 129 Vulnerabilities and Actively Exploited Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android Security Update Google has released its highly anticipated March 2026 Android Security Bulletin, delivering critical fixes for 129 security vulnerabilities across the Android ecosystem. This massive update represents one of the highest numbers of patches issued in a single …

Threat Actors Deploy ‘AuraStealer’ Infostealer with 48 C2 Domains and Active Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new information-stealing malware called AuraStealer has been making its presence felt across the cybersecurity landscape since mid-2025. Developed and actively maintained by a group of Russian-speaking individuals, the malware first appeared on underground hacker forums in July 2025, shortly …

Chrome Gemini Vulnerability Lets Attackers Access Victims’ Camera and Microphone Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Gemini Vulnerability A high-severity security vulnerability has been discovered in Google Chrome’s integrated Gemini AI assistant, exposing users to unauthorized camera and microphone access, local file theft, and phishing attacks, all without requiring any user interaction beyond launching the …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PoC Exploit Released Windows Error Reporting ALPC Privilege Escalation A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides within the Windows Error Reporting (WER) service. The vulnerability …

PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PoC Exploit Released Windows Error Reporting ALPC Privilege Escalation A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides …

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo Browser UXSS Flaw A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of …

DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo Browser UXSS Flaw A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of …