Microsoft Released Patches for RoguePlanet Defender Zero-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 9, 2026 Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain …

New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 9, 2026 A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious …

Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 9, 2026 Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending specially crafted network traffic. Tracked as CVE-2026-0288, the flaw carries …

Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 9, 2026 IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. A threat actor operating …

Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 9, 2026 AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections tied to credential access and living-off-the-land binaries (LOLBins). Recent analysis …

PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A newly identified strain of Android spyware called PromptSpy has become the first mobile malware known to call on generative AI while it is actually running on a victim’s device. Rather than relying purely on hardcoded commands, …

ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed …

Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to …

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 8, 2026 A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, …

DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DuckDuckGo has rolled out native YouTube ad blocking across its browser applications, automatically stripping pre-roll and mid-roll video ads without requiring users to install third-party extensions. The feature works across YouTube and other video platforms, marking a significant shift in …