New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 16, 2026 A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad …

Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 16, 2026 Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing …

CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 16, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle …

Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 16, 2026 A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, …

F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 16, 2026 F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, warning that unauthenticated attackers could exploit them to trigger memory corruption, crash worker processes, or, in the worst case, execute arbitrary code. The flaws, …

Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend? 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Destiny Stealer Destiny Stealer activity is rising across Europe and the US, putting corporate accounts, remote access, email data, and sensitive business information at risk. A single infected endpoint can expose passwords, session cookies, VPN details, Outlook …

GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 OpenAI’s GPT-5.6 Sol Ultra model independently constructed a complete, working exploit chain for Google Chrome, using nothing but publicly available security patch commits as its starting point. Researchers from Hacktron tasked three frontier AI models, GPT-5.6 Sol …

Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Threat actors are hijacking Anthropic’s Claude AI platform and Google Ads to trick Mac users into infecting themselves with a dangerous new information-stealing malware called MacSync Stealer, according to Zscaler Threat Hunting. The infection begins when a …

Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Critical Cursor 0day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution A critical unpatched vulnerability in Cursor, the popular AI-powered code editor used by over 7 million developers, allows attackers to achieve arbitrary code …

Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Toronto, Canada, July 15th, 2026, CyberNewswire Enterprise-grade binary software verification for one project, one team, or one compliance deadline — without an annual commitment. According to Insignary Inc., a leader in software supply chain security and binary …