OCRFix Botnet Trojan Leveraging ClickFix Phishing and EtherHiding to Conceal Blockchain-Based Command Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified botnet trojan campaign, dubbed OCRFix, has been discovered combining social engineering tricks with blockchain-based command infrastructure to quietly build a network of compromised machines. The campaign blends the well-known ClickFix phishing technique with EtherHiding — a method …

Tire Pressure Systems in Toyota, Mercedes, and Other Major Car Brands Enable Silent Vehicle Tracking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tire Pressure Systems Vehicle Tracking Tire Pressure Monitoring Systems (TPMS) in vehicles from Toyota, Renault, Hyundai, and Mercedes broadcast unencrypted tire data, enabling low-cost passive tracking of cars and drivers. Researchers from IMDEA Networks and partners have revealed that a …

CISA Warns of RESURGE Malware Exploiting 0-Days to Breach Ivanti Connect Secure Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware variant named RESURGE is actively targeting Ivanti Connect Secure devices by exploiting a critical zero-day vulnerability, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue a formal warning. The malware is built to survive …

Angular SSR Request Vulnerability Allows Attackers to Trick Applications into Sending Unauthorized Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Angular SSR Request Vulnerability A critical vulnerability has been discovered in Angular Server-Side Rendering (SSR) that could allow attackers to trick applications into sending unauthorized requests. Tracked as CVE-2026-27739, this Server-Side Request Forgery (SSRF) flaw poses a severe risk to …

Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A browser extension that once earned a Featured badge from Google quietly turned into a remote code execution tool after its ownership changed hands, exposing thousands of users to covert script injection and full browser security header stripping. The campaign, …

US Military Reportedly Used Claude in Iran Strikes Despite Trump’s Ban

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

US Military Reportedly Used Claude The U.S. Department of Defense deployed Anthropic’s Claude AI during Operation Epic Fury, a joint offensive with Israel against Iran on February 28, just hours after President Trump designated Anthropic as a national security “supply …

Hacked Prayer App Used as Cyber Weapon During US-Israel Strikes on Iran

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hacked Prayer App As Israeli and US forces launched joint preemptive airstrikes on Tehran, a sophisticated cyber-psychological operation unfolded simultaneously. According to a report by Wired Middle East, millions of Iranian citizens and military personnel were jolted awake not only …

AWS Power Outage in Middle East Triggers Major Disruption to EC2 and Networking Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AWS Power Outage A major power outage in the AWS me-central-1 (Middle East) region on March 1, 2026, resulted from an unusual physical incident where external objects struck a data center, triggering sparks and a fire. The event caused significant …

OpenClaw 0-Click Vulnerability Allows Malicious Websites to Hijack Developer AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-interaction vulnerability in OpenClaw, one of the fastest-growing open-source AI agent frameworks in history, has been discovered by Oasis Security researchers, allowing any malicious website to silently seize full control of a developer’s AI agent without requiring plugins, …

Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Infoblox Threat Intel have uncovered a highly sophisticated phishing campaign that exploits the foundational plumbing of the internet to bypass enterprise security controls. In a novel evasion tactic, threat actors are weaponizing the .arpa top-level domain (TLD) and utilizing …