PromptSpy – First Known Android AI Malware Uses Google’s Gemini for Decision-making

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first known Android malware family to weaponize a generative AI model, specifically Google’s Gemini, as part of its active execution flow. Discovered in February 2026, the malware represents a significant evolutionary step in mobile threats and follows ESET’s earlier …

Threat Actors Using Fake Google Forms Site to Harvest Google Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is targeting job seekers through fake Google Forms websites designed to steal login credentials. The campaign uses sophisticated domain impersonation techniques to trick victims into revealing their Google account information. Attackers have registered a fraudulent domain …

CISA Warns of Honeywell CCTV Products Vulnerability Leads to Account Takeovers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical advisory warning regarding a severe vulnerability affecting Honeywell CCTV products, published on February 17, 2026, under advisory ICSA-26-048-04. The alert details a high-severity security flaw that could allow malicious actors to completely hijack user accounts and gain unauthorized …

Hackers Leveraging nslookup.exe to Stage Payloads via DNS Using Clickfix Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickfix Attack Using nslookup A sophisticated evolution of the ClickFix social engineering campaign, in which threat actors are now abusing the legitimate Windows utility nslookup.exe to deploy malicious payloads via DNS queries. This technique, noticed by Researcher Muhammad Hassoub, marks …

XWorm Malware Delivered via Fake Financial Receipts Targeting Windows Systems to Steal Logins and Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign is actively targeting Brazilian and Latin American (LATAM) businesses using fake bank receipts to deliver XWorm v5.6, a commodity remote access trojan (RAT) capable of stealing credentials, hijacking sessions, and enabling downstream ransomware deployment. The …

Hackers Leveraging Emoji Code to Hide Malicious Code and Evade Security Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have begun using an obfuscation technique called emoji smuggling to hide malicious code from security systems. This attack method exploits Unicode encoding and emoji characters to bypass traditional security filters that scan for suspicious ASCII text patterns. Standard …

Critical Authentication Bypass in better-auth API Keys Plugin Allows Unauthenticated Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the better-auth API keys plugin allows unauthenticated attackers to mint privileged API keys for arbitrary users. The flaw, tracked as CVE-2025-61928, affects all versions of the better-auth library prior to 1.3.26 — a package …

AI Dev Tool Cline’s npm Token Hijacked by Hackers for 8 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A compromised publish token gave attackers brief but concerning access to the Cline CLI npm package, exposing developers who installed it during an 8-hour window on February 17, 2026. The incident highlights the growing risk of supply chain attacks targeting …

Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cryptocurrency mining campaign has emerged, targeting systems through external storage devices with the ability to compromise even air-gapped environments. The malware operates as a multi-stage infection that prioritizes mining Monero cryptocurrency while establishing persistent mechanisms to resist removal. …

Microsoft Defender Unveils Centralized Script Library with Copilot Analysis for Enhanced Live Response

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has introduced a new Library Management experience in Microsoft Defender for Endpoint, designed to fundamentally transform how security analysts manage the scripts and tools they rely on during live response investigations. Announced on February 16, 2026, the enhancement addresses …