Cyber Security

Cyber Security
Cyber Security

New ClickFix Campaign Uses macOS Script Editor to Deliver Atomic Stealer

new-clickfix-campaign-uses-macos-script-editor-to-deliver-atomic-stealer

A newly discovered ClickFix campaign is targeting macOS users through a technique that completely bypasses Terminal, using Script Editor to drop the Atomic Stealer infostealer onto compromised systems. This campaign marks a clear shift in how attackers are responding to Apple’s tightening security controls — a sharp reminder that social engineering can work around almost […]

Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers

hackers-impersonate-linux-foundation-leader-in-slack-to-target-open-source-developers

Open source developers are facing a growing and sophisticated threat — one that does not rely on complex exploits or hidden vulnerabilities but instead uses something far simpler: trust. A social engineering campaign is actively targeting developers through Slack, where an attacker poses as a respected Linux Foundation community leader to trick victims into downloading […]

Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer

hackers-used-eviltokens,-clickfix-campaign-to-attack-claude-code-users-with-amos-stealer

EvilTokens and AMOS redefine modern phishing attacks Two significant threat campaigns from March 2026, one abusing Microsoft’s OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS infostealer against macOS users who work with AI development tools like Claude Code. The EvilTokens campaign represents a significant evolution in phishing tactics because it […]

Microsoft Confirms Recent Windows 11 Update Breaks Start Menu Function

microsoft-confirms-recent-windows-11-update-breaks-start-menu-function

Microsoft has acknowledged a server-side issue that disrupted Start Menu search functionality for a subset of Windows 11 23H2 users, and has since deployed a fix to address the problem without requiring users to install any additional updates. The issue, officially tracked under release health identifier WI1273488, began surfacing around April 6, 2026, and was […]

CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User

cups-vulnerability-chain-enables-remote-attacker-to-execute-malicious-code-as-root-user

A critical vulnerability chain in the Common Unix Printing System (CUPS) that allows unauthenticated remote attackers to execute arbitrary malicious code with root system privileges. Security researcher Asim Viladi Oglu Manizada and his team discovered two zero-day flaws, officially tracked as CVE-2026-34980 and CVE-2026-34990, that affect CUPS versions 2.4.16 and older. The sophisticated attack chain […]

Hackers Use Fake Gemini npm Package to Steal Tokens From Claude, Cursor, and Other AI Tools

hackers-use-fake-gemini-npm-package-to-steal-tokens-from-claude,-cursor,-and-other-ai-tools

A new supply chain attack has surfaced targeting software developers who work with AI coding tools. On March 20, 2026, a threat actor published a malicious npm package named gemini-ai-checker under the account gemini-check, presenting it as a simple utility to verify Google Gemini AI tokens. The package looked credible enough to fool developers — but beneath its […]

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

cisa-warns-of-fortinet-0-day-vulnerability-actively-exploited-in-attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-35616, a critical improper access control vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, mandating federal agencies to remediate by April 9, 2026. CVE-2026-35616 is a critical-severity flaw rooted in CWE-284 (Improper Access Control), carrying a CVSS score […]

Googles Bug Bounty Program Hits All-Time High With $17 Million in 2025 Payouts

googles-bug-bounty-program-hits-all-time-high-with-$17-million-in-2025-payouts

Google’s Vulnerability Reward Program (VRP) celebrated its 15th anniversary in 2025 by breaking every payout record in its history. The tech giant awarded a staggering $17 million to external security researchers worldwide, representing a massive 40% surge compared to 2024. Over 700 ethical hackers from across the globe successfully identified and responsibly disclosed vulnerabilities, proving […]