PoC Exploit Released for libssh2 Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A public proof-of-concept (PoC) exploit for the critical libssh2 remote code execution vulnerability tracked as CVE-2026-55200 is now available, significantly increasing the risk of real‑world attacks against …

Browser-in-the-Browser Kit Uses Fake Software Errors to Deliver Malware Installers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified attack campaign is using a sophisticated Browser-in-the-Browser (BitB) kit to trick users into downloading malware disguised as legitimate software installers. The technique combines convincing …

GhostShell Malware Uses mTLS Implant and Telegram Dead-Drop to Target Ukrainian Drone Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A newly identified malware cluster known as GhostShell has been found actively targeting Ukraine’s drone operations and its broader defense supply chain. The campaign uses a sophisticated …

Red-Team AI Tool Vulnerabilities Let Attackers Exfiltrate API Keys and Compromise Operators’ Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A first-of-its-kind security analysis of 12 widely deployed agentic offensive-security tools reveals critical architectural flaws that allow adversaries to steal LLM API keys, establish persistent footholds, and …

Hackers Exploit Unpatched SharePoint Servers to Deploy Ransomware and Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 Unpatched on-premises SharePoint servers have become a prime target for sophisticated threat actors using known security flaws to break in, plant ransomware, and leave behind hidden backdoors. …

Malicious AI Agent Skill Bypasses Security Scans and Seized Full Control of Over 26,000 Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A malicious AI “skill” created as part of a controlled security experiment has exposed critical weaknesses in modern AI agent ecosystems, successfully bypassing security scanners and compromising …

FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 24, 2026 A large-scale, ongoing credential-harvesting campaign dubbed “FortiBleed” has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since …