CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 1–10 of 156 articles
WEBAPP BleepingComputer

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. The Window Hopper added in this release works like the standard ALT + TAB Windows feature, but it only works for the currently focused app, helping users switch back and forth between its windows. "Once the utility is enabled, press the configurable Alt + backtick shortcut to cycle through that app's windows without stepping through everything else on your desktop," Microsoft explains. "It is especially useful when you're juggling multiple browser windows, terminals, File Explorer windows, or editor instances." Those who want to customize the default activation keyboard shortcut can also do so in PowerToys settings to switch to the next and previous app window.

Aug 25, 2026, 01:51 PM Read more →
NETWORK BleepingComputer

Police arrests dozens of suspects in global cybercrime crackdown

Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. The "Operation Jackal IV" international joint action targeted West African criminal networks between November 2025 and June 2026. The operation also focused on disrupting the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud. Most commonly, Black Axe and similar criminal rings are targeting victims in romance scams, cryptocurrency and investment scams, or business email compromise fraud, but they've often also been linked to violent crimes. During Operation Jackal IV, Argentinian law officers made 17 arrests, and they linked 196 suspects to a major Crime-as-a-Service network that provided West African organized crime groups with web domains and money-laundering support.

Aug 25, 2026, 10:53 AM Read more →
API Palo Alto Unit 42 Ransomware

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Aug 25, 2026, 10:00 AM Read more →
NETWORK Security Affairs CVE-2026-21962 ↗

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. An attacker does not need an account or valid credentials. With network access, they can exploit the flaw remotely through HTTP and potentially compromise the affected server. Successful exploitation could allow the attacker to access, modify or delete critical data, potentially gaining broad access to information available through the affected components. “Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data,” CISA reports. The vulnerability also has a scope-change impact, meaning an attacker who exploits it could potentially affect other systems or applications connected to the vulnerable Oracle components. The flaw affects versions: 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. In practical terms, this is dangerous because an internet-accessible Oracle WebLogic proxy component could provide an attacker with a path into critical backend systems without requiring authentication. In March 2026, CloudSEK researchers detected attacks targeting several known flaws in Oracle WebLogic against its honeypot network. Attackers also targeted CVE-2026-21962 along with older WebLogic RCE vulnerabilities, including CVE-2020-14882/14883, CVE-2020-2551 and CVE-2017-10271. “This report analyzes attack data collected from a high-interaction honeypot simulating a vulnerable Oracle WebLogic Server (v14.1.1.0.0) over a 12-day period (Jan 22 – Feb 3, 2026). The primary focus is the immediate and widespread exploitation of the newly disclosed, critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-21962 (CVSS: 10.0).” ” reads the report published CloudSEK. “In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE). This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.” According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog. Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. CISA orders federal agencies to fix the flaw by August 27, 2026. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, CISA)

Aug 25, 2026, 08:48 AM Read more →
WEBAPP Security Affairs

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control infrastructure. Over the past month alone, McAfee WebAdvisor blocked more than 6,300 user attempts to reach these sites. WeedHack was first spotted in early June 2026 when McAfee researcher Aayush Tyagi documented a Malware-as-a-Service operation that had been running since January and had logged 116,464 infected systems, adding between 2,000 and 3,000 new victims every day. The operation offered a free tier that anyone with a Discord account could access, a premium tier with webcam surveillance capability for $5 a month, and a dashboard letting operators view stolen credentials, configure custom payloads, and monitor victims in real time. It spread through fake Minecraft client websites, YouTube videos linking to malicious downloads, and SEO poisoning that pushed those fake sites to the top of search results for popular Minecraft tool names. The malware stole session cookies, passwords, browser data, and cryptocurrency wallet contents, and used EtherHiding, a technique that fetches the attacker’s active server address from the Ethereum blockchain, to maintain contact with its infrastructure even when individual servers were shut down. “During our investigation of this campaign, we observed that most of these websites appear legitimate, as they are well-crafted and often mimic legitimate websites. We observed a series of dedicated brand-impersonation attacks targeting several popular Minecraft clients.” reads the report published by McAfee. “We published the original article in the first week of July, and, as a result, we’ve seen a disruption in WeedHack’s campaign: its C2 server is no longer active. Consequently, we have observed a shift in tactics by these attackers.  “ The dashboard is gone. The distribution sites are not. Each fake website copies the real tool’s features, FAQs, installation steps, developer information and even links to legitimate GitHub repositories. The sites look detailed and convincing, so most users have little reason to suspect anything. The attackers also use search rankings to reach victims. Researchers found that the first two Google results for “Xenon Client,” a popular Minecraft client, led to fake sites distributing WeedHack. The sites offered installation guides, free and paid downloads, and links to the real Xenon Client GitHub repository. A player searching for the tool, clicking the first result and downloading the file could easily end up installing malware. The campaigns exploit a structural weakness in the Minecraft modding community: many popular tools don’t have official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; the attackers built one and ranked it above the genuine GitHub repository. 22qq-client.com does the same for a Crystal PVP mod. For nova-client.com, the researchers specifically noted that the credits section lists generic team names instead of anyone who actually worked on the project, which is one of the cleaner ways to spot an impersonation if you know who the real developers are. One site in the campaign was built using lovable.app, an AI-powered web application builder that accepts natural language instructions and produces working sites. The platform is legitimate; the use here is not. The ready availability of tools like this means the cost and technical skill required to launch a new convincing fake gaming site is now close to zero. McAfee found that most malicious links came through Discord (49.6%), followed by MediaFire (23.4%), GitHub (8.2%) and Dropbox (4.6%). One Discord channel promoting fake DonutSMP clients had more than 1,900 members, while another site offered eight different mods that all delivered the same malware. The campaign also spread through trusted Minecraft communities such as Planet Minecraft and EndMods, making the scams harder to spot because users already trusted these platforms. McAfee recommends downloading mods and clients only from official developer repositories or trusted platforms such as Modrinth and CurseForge. If a tool asks you to disable antivirus protection, treat it as malware. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, malware)

Aug 25, 2026, 07:15 AM Read more →
NETWORK The Hacker News

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked

Aug 25, 2026, 12:43 PM Read more →
NETWORK The Hacker News

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development

Aug 25, 2026, 11:33 AM Read more →
NETWORK The Hacker News CVE-2026-21962 ↗

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Aug 25, 2026, 06:12 AM Read more →
NETWORK BleepingComputer

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet.

Aug 24, 2026, 09:14 PM Read more →
API BleepingComputer

South Korean startup platform breach exposes key management failures

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect.

Aug 24, 2026, 02:00 PM Read more →