Cybersecurity News
-
Cisco Patches Actively Exploited Firewall Flaw
Cisco published an advisory on Aug. 11 warning that a vulnerability in its firewall software allows an unauthenticated, remote attacker to force affected devices to reload unexpectedly, producing a denial-of-service condition. The…
-
Zoom Patches Annotation Vulnerability Chain Developed With AI Assistance
Zoom released patches on Aug. 11 for four vulnerabilities, three of which form an exploit chain in the company’s annotation feature that allows one meeting participant to execute code on another participant’s…
-
Over 700 Malicious Chrome VPN Extensions Routing Traffic
Socket’s Threat Research Team has identified 737 free VPN and proxy extensions in the Chrome Web Store that route users’ entire browser sessions through proxy infrastructure controlled by a single operator. The…
-
Fake Resume Malware Campaign Targets HR Departments
Cybersecurity researchers are warning about a new attack campaign targeting human resources departments with malicious job applications disguised as legitimate resumes. According to security research from Aryaka and reporting by Cybernews, attackers…
-
SQL Injection Flaw in Popular WordPress Plugin Exposes Over 400k Sites
A critical SQL injection vulnerability discovered in a widely used WordPress plugin has placed more than 400,000 websites at risk of database data exposure. Security researchers at Wordfence identified the flaw in…
-
Microsoft Releases April 2026 Windows Security Updates
Microsoft has released its March 2026 Patch Tuesday security updates, addressing 83 vulnerabilities across Windows, Office, SQL Server, Azure, and developer platforms. Among the fixes are eight critical vulnerabilities, along with two…
-
AI Is Becoming One of Cybersecurity’s Most Powerful Bug Hunters
Artificial intelligence is rapidly transforming how security vulnerabilities are discovered and fixed. Recent developments from major AI companies suggest that automated security research may soon become a standard part of software development.…
-
Chrome Extension Supply Chain Attack Turns Trusted Tools Into Malware
A newly uncovered campaign shows how attackers can quietly transform legitimate browser extensions into malware—simply by acquiring them. As reported by TheHackerNews, security researchers recently discovered that two Google Chrome extensions turned…
-
Fake Google Meet Update Can Secretly Give Attackers Control of Your PC
Security researchers at Malwarebytes have newly discovered a phishing campaign abusing legitimate Windows device management features to take control of victims’ computers without installing traditional malware. Instead of tricking users into downloading…
