73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks …

Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 26, 2026 A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued …

New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented …

CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 25, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly …

Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

April 25, 2026 Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI …

Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and …

Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

State-sponsored threat actors are actively targeting Cisco Firepower devices by chaining known vulnerabilities to deploy a highly customized backdoor. Cisco Talos recently discovered that the espionage-focused threat group UAT-4356 is …

Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of several Chromium-based …