OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub …

Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A newly discovered malware family is making its way onto systems worldwide by hiding inside fake software installers that look completely legitimate. Researchers have identified a campaign …

Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Google has released a critical security update for its Chrome browser, pushing the Stable channel to version 149.0.7827.196/197 for Windows and Mac, and 149.0.7827.196 for Linux. The …

Anthropic Accuses Alibaba of ‘Illicitly’ Accessing Its Claude AI Models in Largest Known Distillation Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Anthropic has formally accused Chinese tech and e-commerce giant Alibaba of orchestrating a massive, unauthorized extraction campaign targeting its Claude AI model, marking what the company describes …

Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint …

Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Threat actors are once again exploiting the trust people place in everyday workplace tools. A newly discovered phishing campaign is using fake Microsoft Teams notifications to trick …

Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A new and deceptive malware campaign has been uncovered, one that turns an everyday browser extension into a dangerous tool for system compromise. Security researchers have identified …

EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps  

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 EvilTokens  EvilTokens is drawing attention in phishing investigations for abusing Microsoft Device Code authentication and hiding key parts of its attack flow from static URL analysis.    In a recent analysis, …

Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A sophisticated threat actor is actively targeting SD-WAN infrastructure at a major service provider. The campaign culminated in the exploitation of a zero-day privilege escalation vulnerability, now …

Authorities Disrupt Password-Stealing Malware StealC Infrastructure in Global Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Europol and law enforcement partners across multiple countries have dealt a significant blow to the cybercriminal ecosystems powering StealC, Amadey, and SocGholish malware, three widely deployed tools …