Hackers Abuse Notepad++ Plugins to Compromise Your System Silently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group’s tactics since mid-summer 2026. Uncovered by Ukraine’s CERT-UA, the infection begins …

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a covert channel for receiving commands and moving data. This approach …

Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging …

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two …

Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1, the issue impacts Exim versions …

Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, …

New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords. The tool is marketed to criminals as both an information stealer and a remote access trojan, giving …

Google Launches CodeMender AI Agent to Find, Validate, and Patch Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 Google has introduced CodeMender, a new AI-powered code security agent designed to find, validate automatically, and patch vulnerabilities at machine speed, as organizations face a surge in AI-driven cyber threats targeting software supply chains. The launch marks …

Microsoft Defender for Office 365 Adds New Prompt Injection Protection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot. This update reflects the evolving threat landscape, where attackers increasingly …

New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 23, 2026 A newly reported research effort tied to the Kimi K3 AI agent has surfaced multiple authenticated remote code execution (RCE) paths in Redis, one of the world’s most widely deployed in-memory data stores. The findings shared by …