DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo Browser UXSS Flaw A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of …

MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MSHTML Framework 0-Day Exploited by APT28 A zero-day vulnerability in the Microsoft HTML (MSHTML) framework was actively exploited in the wild. The vulnerability, tracked as CVE-2026-21513, allows attackers to bypass security features and execute arbitrary files. With a CVSS score …

Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude AI Suffers Global Outage On March 2, 2026, Anthropic’s artificial intelligence assistant, Claude, experienced a significant global outage that disrupted workflows for users and developers worldwide. Organizations relying on the AI model for daily threat intelligence reporting, code generation, …

Criminal IP to Present Decision-Ready Threat Intelligence at RSAC™ 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, March 2nd, 2026, CyberNewswire March 23–26, 2026 | Booth N-6555, Moscone Center, San Francisco Criminal IP, an AI-powered cybersecurity platform specializing in Attack Surface Management (ASM) and Cyber Threat Intelligence (CTI), will participate in the …

GTFire Phishing Scheme Abuses Google Services to Evade Detection and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign called GTFire is abusing two of Google’s most trusted services — Firebase and Google Translate — to harvest login credentials from victims around the world. What makes this campaign dangerous is its ability to hide malicious …

Link11 Releases European Cyber Report 2026: DDoS Attacks Become a Constant Threat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Frankfurt am Main, Germany, March 2nd, 2026, CyberNewswire 12,388 minutes of continuous attacks – more than eight days straight 509 terabytes of cumulative attack volume 70% of companies targeted in an initial attack are hit again Link11 has published its …

Hackers Attacking SonicWall Firewalls from 4,000+ unique IP Addresses to Exploit Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale reconnaissance campaign is actively targeting SonicWall firewalls across the internet, with attackers using more than 4,000 unique IP addresses to map vulnerable devices before launching exploitation attempts. Between February 22 and February 25, 2026, threat actors generated 84,142 …

OCRFix Botnet Trojan Leveraging ClickFix Phishing and EtherHiding to Conceal Blockchain-Based Command Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified botnet trojan campaign, dubbed OCRFix, has been discovered combining social engineering tricks with blockchain-based command infrastructure to quietly build a network of compromised machines. The campaign blends the well-known ClickFix phishing technique with EtherHiding — a method …

Tire Pressure Systems in Toyota, Mercedes, and Other Major Car Brands Enable Silent Vehicle Tracking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tire Pressure Systems Vehicle Tracking Tire Pressure Monitoring Systems (TPMS) in vehicles from Toyota, Renault, Hyundai, and Mercedes broadcast unencrypted tire data, enabling low-cost passive tracking of cars and drivers. Researchers from IMDEA Networks and partners have revealed that a …

CISA Warns of RESURGE Malware Exploiting 0-Days to Breach Ivanti Connect Secure Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware variant named RESURGE is actively targeting Ivanti Connect Secure devices by exploiting a critical zero-day vulnerability, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue a formal warning. The malware is built to survive …