FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known Chinese cyberespionage group has taken a major step forward in its hacking capabilities. The threat actor, tracked as FishMonger, has brought its SprySOCKS backdoor to Windows for the …

ErrTraffic MaaS Uses Fake reCAPTCHA and Cloudflare Turnstile Lures to Execute PowerShell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A new and rapidly growing cybercrime tool called ErrTraffic is making waves across the threat landscape, targeting internet users through cleverly disguised verification screens. The framework tricks …

Multiple JetBrains IDE Plugins 70,000+ Installs Caught Stealing AI keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A large-scale malware campaign has been uncovered on the JetBrains Marketplace, where at least 15 malicious IDE plugins were found stealing sensitive API keys from developers. These …

CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 CISA has added a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaw affects …

Fortra Access Manager Vulnerability Enables Remote Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Fortra has disclosed a critical security vulnerability in its Core Privileged Access Manager (BoKS) that could allow remote attackers to execute arbitrary commands on affected systems. CVE-2026-9862 …

U.S. Commerce Dept Imposes Export Controls on Anthropic’s Claude Mythos 5 and Fable 5

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 The Bureau of Industry and Security (BIS) has issued a landmark “Is Informed” letter to Anthropic CEO Dario Amodei, mandating that the company obtain an individually validated …

Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A sophisticated supply chain attack has targeted the Mastra-AI npm ecosystem, with researchers from Microsoft and Socket identifying over 141 compromised packages designed to silently deploy an …

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 AIRecon is an autonomous penetration testing agent that runs entirely offline, combining a self-hosted Ollama LLM with a Kali Linux Docker sandbox to automate end-to-end security assessments …

Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows …

Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 17, 2026 Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users …