ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed the next day. In a breach notification …

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream. The …

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers. The pages claim to inspect a device, report serious …

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AliExpress’s homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears to power an aggressive device-fingerprinting system while producing an unexpected real-world side effect: interfering with …

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over accounts by knowing only a registered mobile …

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware. …

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in Windows Presentation Foundation (WPF) applications, creating fresh headaches for enterprises …

Multiple Zscaler Client Connector Vulnerabilities Enable RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities affecting Zscaler Client Connector have been disclosed, potentially allowing remote code execution on vulnerable systems. Tracked as CVE-2026-59568, the critical flaw chain enables an unauthenticated and unprivileged attacker …

91 Spring Vulnerabilities Impact 209,000+ Software Components Across Open-Source Ecosystem

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcom has released a major batch of Spring security advisories, with Sonatype tracking 91 CVEs across Spring Framework and related projects. The August 20, 2026 disclosure affects an estimated 209,569 …