Sunday, April 26, 2026
HomeCyber News

Cyber News

SEO Manipulation – Oyster Backdoor and PuTTY-Driven KeyPass Attacks Target IT Admins

Cybersecurity researchers have uncovered a sophisticated malvertising campaign that has been actively targeting IT professionals since early June 2025, using search engine optimization (SEO) poisoning to distribute the dangerous Oyster backdoor through fake versions of popular administrative tools. Campaign Mechanics and Initial Infection Arctic Wolf researchers...

SonicWall SSL VPN Vulnerability Allows Attackers to Launch DoS Attacks on Firewalls

SonicWall has disclosed a significant security vulnerability affecting its Gen7 firewall products that could allow remote attackers to disrupt network services without authentication. The vulnerability, tracked as CVE-2025-40600 and assigned advisory ID SNWLID-2025-0013, was first published on July 29, 2025, with updates released the...

ChatGPT Agent Overcomes Cloudflare “I Am Not a Robot” Verification Checks

ChatGPT-powered agent effortlessly passed Cloudflare’s well-known “I am not a robot” CAPTCHA, the security interstitial designed to stop automated traffic. The clip shows the agent inserting a link into a conversion service and then ticking the checkbox without hesitation, immediately receiving the green-lit “Verifying…”...

Critical AI Vibe Coding Platform Vulnerability Exposes Unauthorized Access to User Private Apps

A critical security vulnerability in Base44, a popular AI-powered "vibe coding" platform recently acquired by Wix, that allowed unauthorized access to private applications built by users. The vulnerability, which has since been patched, could have exposed sensitive enterprise data including internal chatbots, HR operations,...

Chinese Cyberattackers Exploit Software Flaws to Breach Targets

China has constructed an extensive vulnerability collection system that enables its intelligence services and military units to access software flaws for offensive cyber operations, according to a comprehensive analysis of the country's cybersecurity infrastructure. The system, implemented through 2021 regulations, fundamentally reshapes how software...

Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

A sophisticated attack targeting a U.S. chemicals company, where threat actors exploited a critical SAP NetWeaver vulnerability to deploy the elusive Auto-Color backdoor malware. The April 2025 incident represents the first documented case linking CVE-2025-31324 exploitation with Auto-Color deployment, highlighting the evolving threat landscape...