Aggregator
'Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft
AI and browser threats stand out in the 2026 Threat Detection Report
15 лет за «звездочку». 17-летнего школьника обвинили в финансировании терроризма из-за реакций в мессенджере
New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots
Network security has taken another hard hit. Two previously unknown malware strains have emerged, quietly turning routers, IoT devices, and enterprise network equipment into weapons for large-scale distributed denial-of-service (DDoS) attacks and cryptocurrency mining operations. These campaigns mark a clear shift in how threat actors are exploiting the very network infrastructure that organizations depend on […]
The post New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots appeared first on Cyber Security News.
Mitel security advisory (AV26-250)
FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets
A serious operational security failure by Russian state-linked hacking group FancyBear has given security researchers an unusually clear view into an active espionage campaign targeting government and military organizations across Europe. On March 11, 2026, threat intelligence firm Hunt.io published findings on a campaign it tracks as Operation Roundish, based on an exposed open-directory first […]
The post FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets appeared first on Cyber Security News.
调查显示近六成人愿意为保护环境而放弃经济增长
ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions
ConnectWise has issued an urgent security advisory for its ScreenConnect remote desktop software, disclosing a critical cryptographic vulnerability that could allow unauthenticated attackers to extract server-level machine keys and hijack session authentication. The flaw, tracked as CVE-2026-3564, affects all ScreenConnect versions prior to 26.1 and carries a CVSS score of 9.0, placing it firmly in […]
The post ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions appeared first on Cyber Security News.
Хакеры стали экономнее. Они больше не тратят деньги на скупку ворованных учётных данных
GNU security advisory (AV26-249)
CISA official says agency has not seen uptick in cyber threats amid Iran war
CVE-2026-25449 | Shinetheme Traveler Plugin 3.2.2/3.2.3/3.2.6/3.2.8 on WordPress deserialization (EUVD-2026-12821)
Apple security advisory (AV26-248)
CVE-2026-33265 | LibreChat 0.8.1-rc2 LibreChat API/RAG API resource transfer (EUVD-2026-12813)
CVE-2026-3278 | OpenText ZENworks Service Desk 25.2/25.3 cross site scripting (EUVD-2026-12825)
CVE-2025-41258 | danny-avila LibreChat 0.8.1-rc2 JWT Secret access control
LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader
A ransomware group known as LeakNet has been quietly building a more dangerous attack strategy. Until recently, the group averaged about three victims per month — but new evidence shows it is scaling up fast, adding new tools that most security defenses are not built to catch. LeakNet has introduced two notable additions: a social […]
The post LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader appeared first on Cyber Security News.