ZCyberNews
中文

Articles

460 articles

Senate Extends Section 702 Surveillance Authority for 48 HoursINFORMATIONAL
Industry News

Senate Extends Section 702 Surveillance Authority for 48 Hours

The U.S. Senate passed a 48-hour extension of Section 702 surveillance powers, averting a lapse after House chaos. The program, used by the NSA and FBI, collects foreign communications without a warrant.

2 min read
SGLang Vulnerability CVE-2026-5760 Enables Remote Code Execution via GGUF FilesCRITICAL
Vulnerabilities

SGLang Vulnerability CVE-2026-5760 Enables Remote Code Execution via GGUF Files

CVE-2026-5760, a critical 9.8 CVSS flaw in the SGLang inference engine, allows attackers to execute arbitrary code by uploading malicious GGUF model files, compromising AI/ML serving deployments.

CVE-2026-5760
2 min read
The Gentlemen Ransomware Deploys SystemBC Proxy for C2 EvasionHIGH
Malware

The Gentlemen Ransomware Deploys SystemBC Proxy for C2 Evasion

The Gentlemen ransomware-as-a-service group uses the SystemBC SOCKS5 proxy tool to hide command-and-control traffic, according to a Check Point DFIR report analyzing a recent affiliate attack.

3 min readThe Gentlemen
108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram DataHIGH
Malware

108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data

Socket identified 108 malicious Chrome extensions that infected 20,000 users, stealing Google and Telegram session cookies and injecting ads via a shared command-and-control server.

3 min read
AI-Powered Vulnerability Discovery Accelerates Exploit Timelines, StrainsHIGH
AI Security

AI-Powered Vulnerability Discovery Accelerates Exploit Timelines, Strains

Qualys warns that AI agents like Claude Mythos can cut vulnerability discovery time from months to hours, compressing the patch window and overwhelming security teams with a surge of new CVEs.

3 min read
Cloud Security Alliance Warns of AI Vulnerability Storm Post-MythosHIGH
AI Security

Cloud Security Alliance Warns of AI Vulnerability Storm Post-Mythos

The Cloud Security Alliance warns that Anthropic's Claude Mythos model will trigger an 'AI vulnerability storm,' forcing CISOs to manage a 10x surge in code flaws and novel exploit techniques within 18 months.

3 min read
Florida Investigates ChatGPT Role in Campus Shooting ThreatHIGH
AI Security

Florida Investigates ChatGPT Role in Campus Shooting Threat

Florida law enforcement is investigating how a student used ChatGPT to craft a threat of a campus shooting, part of a broader pattern where AI chatbots fail to block dangerous content.

3 min read
Microsoft Office Excel Flaw Exploited in Active AttacksCRITICAL
Vulnerabilities

Microsoft Office Excel Flaw Exploited in Active Attacks

CISA orders federal agencies to patch CVE-2009-0238, a 17-year-old Microsoft Office Excel remote code execution flaw, by April 28, 2026, due to active exploitation.

CVE-2009-0238
3 min read
Mirax Android RAT Infects 220,000 Users via Meta Ads, Creates SOCKS5 ProxyHIGH
Malware

Mirax Android RAT Infects 220,000 Users via Meta Ads, Creates SOCKS5 Proxy

Mirax Android RAT reached over 220,000 users via Meta ads, turning infected devices into SOCKS5 proxies for threat actors to route malicious traffic and steal data from Spanish-speaking victims.

3 min readMirax
Omnistealer Malware Harvests Passwords, Crypto Wallets via Blockchain C2HIGH
Malware

Omnistealer Malware Harvests Passwords, Crypto Wallets via Blockchain C2

Omnistealer malware, detailed by Malwarebytes, steals credentials from 1Password, Bitwarden, NordPass, and Exodus crypto wallets, using the Solana blockchain for stealthy command-and-control communication.

4 min readOmnistealer
Samsung MagicINFO 9 Server Local Privilege Escalation Vulnerability PatchedHIGH
Vulnerabilities

Samsung MagicINFO 9 Server Local Privilege Escalation Vulnerability Patched

CVE-2026-25203, a CVSS 7.8 local privilege escalation flaw in Samsung MagicINFO 9 Server, allows authenticated attackers to gain SYSTEM privileges by exploiting incorrect default permissions on a service.

CVE-2026-25203
3 min read
ATEN Unizon RPC Service Vulnerable to Unauthenticated Denial-of-ServiceHIGH
Vulnerabilities

ATEN Unizon RPC Service Vulnerable to Unauthenticated Denial-of-Service

CVE-2026-5057, with a CVSS score of 7.5, exposes ATEN Unizon to unauthenticated denial-of-service attacks via its RPC service, allowing remote attackers to crash the device management platform.

CVE-2026-5057
3 min read
← PrevPage 30 of 39Next →