M365Pwned – Red Team GUI Toolkit for Microsoft 365 Exploitation via Graph API

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A red teamer operating under the handle OtterHacker has publicly released M365Pwned, a pair of WinForms GUI tools designed to enumerate, search, and exfiltrate data from Microsoft 365 environments using …

ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Linux malware named ClipXDaemon has emerged as a direct financial threat to cryptocurrency users in X11-based desktop environments. Unlike conventional malware that depends on command-and-control (C2) servers …

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nginx UI Vulnerabilities A newly discovered critical vulnerability in Nginx UI allows unauthenticated attackers to download and decrypt full system backups. Tracked as CVE-2026-27944, this flaw is categorized as CWE-306 …

Transparent Tribe’s ‘Vibeware’ Shift Signals Rise of AI-Generated Malware at Industrial Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pakistan-based threat actor APT36, widely known as Transparent Tribe, has shifted away from carefully crafted tools to a new approach called “vibeware” — AI-assisted malware produced in high volumes with …

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ExifTool Flaw Malicious Images Trigger Code Execution on macOS A newly discovered vulnerability is challenging the long-held belief that macOS systems are inherently immune to malware. Security researchers from Kaspersky’s …

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hikvision Multiple Products Vulnerability A severe vulnerability affecting multiple Hikvision products was added to the Known Exploited Vulnerabilities (KEV) catalog on March 5, 2026. Tracked globally under CVE-2017-7921, this security …

Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A wave of counterfeit AI-powered browser extensions has silently breached over 20,000 enterprise environments, compromising the chat histories of employees who routinely used AI tools for work. These malicious Chromium-based …

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns macOS and iOS Vulnerabilities Exploit The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding multiple Apple vulnerabilities currently facing active exploitation. On March 5, …

WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source edge AI system called π RuView is turning ordinary WiFi infrastructure into a through-wall human-sensing platform detecting body pose, vital signs, and movement patterns without a single …