CrowdCyber.com 1 week ago Vibe-Coded 'Sicarii' Ransomware Can't Be Decrypted Dark ReadingVibe-CodedA new ransomware strain that entered the scene last year has poorly designed code and uses Hebrew language that might be a false flag.
CrowdCyber.com 1 week ago WinRAR path traversal flaw still exploited by numerous hackers BleepingComputerWinRAR path traversal flaw still exploited by numerous hackersMultiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for ...
CrowdCyber.com 1 week ago [Research] Analysis of 74,636 AI Agent Interactions: 37.8% Contained Attack Attempts - New "Inter-Agent Attack" Category Emerges https://www.reddit.com/r/netsec/comments/1qp3rpz/research_analysis_of_74636_ai_agent_interactions/
CrowdCyber.com 1 week ago Microsoft Rushes Emergency Patch for Office Zero-Day Dark ReadingMicrosoft Rushes Emergency Patch for Office Zero-DayTo exploit the vulnerability, an attacker would need either system access or be able to convince a user to open a malicious Office file.
CrowdCyber.com 1 week ago SolarWinds Web Help Desk Hit with Multiple RCE and Auth Bypass Vulnerabilities Daily CyberSecuritySolarWinds Web Help Desk Hit with Multiple RCE and Auth Bypass VulnerabilitiesCritical SolarWinds Web Help Desk flaws (CVSS 9.8) allow unauthenticated RCE and auth bypass. Hardcoded credentials also found. Patch immediately.
CrowdCyber.com 2 weeks ago HPE Aruba Patches High-Severity RCE and OpenSSL Flaws Daily CyberSecurityHPE Aruba Patches High-Severity RCE and OpenSSL FlawsHPE patches critical RCE (CVE-2026-23592) in Fabric Composer. Authenticated attackers can seize the OS via backup tools. Update to v7.3.0 immediately.
CrowdCyber.com 2 weeks ago Sandbox Shattered: Critical n8n Flaw (CVSS 9.9) Allows Remote Code Execution Daily CyberSecuritySandbox Shattered: Critical n8n Flaw (CVSS 9.9) Allows Remote Code ExecutionCritical n8n RCE (CVE-2026-1470) lets attackers bypass sandbox defenses via malicious expressions. CVSS 9.9. Check versions 1.123.17 & 2.x now.
CrowdCyber.com 2 weeks ago Fortinet blocks exploited FortiCloud SSO zero day until patch is ready BleepingComputerFortinet blocks exploited FortiCloud SSO zero day until patch is readyFortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-...
CrowdCyber.com 2 weeks ago Microsoft Starts 2026 With a Bang: A Freshly Exploited Zero-Day Dark ReadingMicrosoftThe vendor
CrowdCyber.com 2 weeks ago Critical Telnet Server Flaw Exposes Forgotten Attack Surface Dark ReadingCritical Telnet Server Flaw Exposes Forgotten Attack SurfaceWhile telnet is considered obsolete, the network protocol is still used by hundreds of thousands of legacy systems and IoT devices for remote access.
CrowdCyber.com 2 weeks ago Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor BleepingComputerChinese Mustang Panda hackers deploy infostealers via CoolClient backdoorThe Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and m...
CrowdCyber.com 2 weeks ago Critical sandbox escape flaw found in popular vm2 NodeJS library BleepingComputerCritical sandbox escape flaw found in popular vm2 NodeJS libraryA critical-severity vulnerability in the vm2 Node.js sandbox library, tracked as CVE-2026-22709, allows escaping the sandbox and executing arbitrar...
CrowdCyber.com 2 weeks ago CISA says critical VMware RCE flaw now actively exploited BleepingComputerCISA says critical VMware RCE flaw now actively exploitedCISA has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered U.S. federal agencies to secure their servers wit...
CrowdCyber.com 2 weeks ago DPRK's Konni Targets Blockchain Developers With AI-Generated Backdoor Dark ReadingDPRKThe North Korean threat group is using a new PowerShell backdoor to compromise development environments and target cryptocurrency holdings.
CrowdCyber.com 2 weeks ago Nearly 800,000 Telnet servers exposed to remote attacks BleepingComputerNearly 800,000 Telnet servers exposed to remote attacksInternet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical auth...
CrowdCyber.com 2 weeks ago CVSS 9.8 Sandbox Escape: Critical vm2 Flaw Exposes Millions of Apps Daily CyberSecurityCVSS 9.8 Sandbox Escape: Critical vm2 Flaw Exposes Millions of AppsCVSS 9.8 vm2 flaw (CVE-2026-22709) affects 3.7 million users, allowing total sandbox escape via async functions. Update to v3.10.2 immediately.
CrowdCyber.com 2 weeks ago New ClickFix attacks abuse Windows App-V scripts to push malware BleepingComputerNew ClickFix attacks abuse Windows App-V scripts to push malwareA new malicious campaign mixes the ClickFix method with fake CAPTCHA and a signed Microsoft Application Virtualization (App-V) script to ultimately...
CrowdCyber.com 2 weeks ago New malware service guarantees phishing extensions on Chrome web store BleepingComputerNew malware service guarantees phishing extensions on Chrome web storeA new malware-as-a-service (MaaS) called 'Stanley' promises malicious Chrome extensions that can clear Google's review process and p...
CrowdCyber.com 2 weeks ago Code by AI: KONNI APT Targets Crypto Devs with “Polished” Backdoor Daily CyberSecurityCode by AI: KONNI APT Targets Crypto Devs with "Polished" BackdoorKONNI APT targets APAC developers with AI-generated malware disguised as crypto projects. The "polished" backdoor steals wallets & credenti...
CrowdCyber.com 2 weeks ago Microsoft patches actively exploited Office zero-day vulnerability BleepingComputerMicrosoft patches actively exploited Office zero-day vulnerabilityMicrosoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks.