Cyber Security

Cyber Security
Cyber Security

Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution

chrome-security-update-fixes-26-vulnerabilities-allowing-remote-code-execution

Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel update rolls out versions 146.0.7680.153 and 146.0.7680.154 for Windows and macOS, while Linux users will receive version 146.0.7680.153. This critical patch cycle is designed to […]

Anthropic Launches Projects Feature for Claude Cowork Desktop

anthropic-launches-projects-feature-for-claude-cowork-desktop

Anthropic is expanding Claude Cowork Desktop with a new Projects feature designed to keep files, instructions, and task context organized inside a single workspace. For paid users, the update makes it easier to start from scratch, import an existing chat, or connect a local folder so Claude can continue work without losing the thread between […]

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

windows-11-march-update-breaks-microsoft-teams-and-onedrive-sign-ins

Windows 11 March Update Breaks Teams Microsoft has acknowledged a significant bug introduced by its March 2026 cumulative update that is preventing users from signing into Microsoft Teams Free, OneDrive, and several other Microsoft applications on Windows 11 devices. The issue, tied to the KB5079473 update released on March 10, 2026, has left affected users […]

Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data

hackers-compromised-7,500+-magento-websites-to-upload-hidden-malicious-files-and-steal-data

A sweeping cyberattack campaign has compromised more than 7,500 Magento-powered e-commerce websites since late February 2026, with attackers uploading hidden malicious files into publicly accessible web directories across thousands of domains. The attack has spread to over 15,000 hostnames, affecting commercial brands, government agencies, universities, and non-profit organizations spanning multiple countries, making it one of […]

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

new-voidstealer-variant-bypasses-chrome-abe-without-injection-or-privilege-escalation

A newly identified variant of the VoidStealer infostealer has drawn serious attention from the security community after it became the first malware known to bypass Google Chrome’s Application-Bound Encryption (ABE) without requiring code injection or elevated system privileges. The variant, introduced in VoidStealer version 2.0 on March 13, 2026, uses a debugger-based technique to silently […]

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

silentconnect-uses-vbscript,-powershell-and-peb-masquerading-to-deploy-screenconnect

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on victim systems. Once deployed, ScreenConnect gives the attacker full hands-on keyboard control over the compromised […]

CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks

cisa-warns-of-zimbra-collaboration-suite-vulnerability-exploited-in-attacks

CISA Warns Zimbra Collaboration Suite Vulnerability Exploit CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. Organizations utilizing Zimbra must urgently prioritize remediation to prevent unauthorized access and potential data compromise. […]

WaterPlum Deploys New StoatWaffle Malware in VSCode-Based Supply Chain Campaign

waterplum-deploys-new-stoatwaffle-malware-in-vscode-based-supply-chain-campaign

A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines.​ WaterPlum has been running a campaign known as “Contagious Interview” for some time, drawing victims in through fake job […]

Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware

cisco-firewall-0-day-vulnerability-exploited-in-the-wild-to-deploy-interlock-ransomware

An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. Cisco disclosed the flaw on March 4, 2026; it allows unauthenticated remote attackers to execute arbitrary Java code as root. Amazon threat intelligence researchers discovered Interlock exploiting this vulnerability 36 days before […]

OpenAI Launches GPT-5.4 Mini and Nano to Provide Answers 2X Faster

openai-launches-gpt-5.4-mini-and-nano-to-provide-answers-2x-faster

OpenAI Launches GPT-5.4 Mini and Nano OpenAI has officially launched GPT-5.4 mini and GPT-5.4 nano, releasing its most capable small models designed to handle high-volume, latency-sensitive workloads. The new mini iteration offers a significant performance upgrade over the previous GPT-5 mini across reasoning, coding, tool use, and multimodal understanding, while running more than twice as […]