Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Security

Google Unveils New AI Security Arsenal to Prevents Real-World Cyberattack

Google has achieved a cybersecurity milestone by using artificial intelligence to prevent an active exploit attempt in the wild, marking the first ti…

FBI Warns of Deepfake Phishing Campaign Impersonating U.S. Officials

The Federal Bureau of Investigation (FBI) recently warned of a widespread deepfake phishing campaign targeting U.S. federal and state officials and …

Critical Flaw Lets Attackers Hijack Train Brakes With $500 Radio Equipment

A critical security vulnerability in America's railway system allows attackers to remotely hijack train brake controls using inexpensive radio eq…

Critical Browser-Based Attack Chain Compromises Internal Networks Through Single Website Visit

Security researchers have demonstrated a devastating new attack method that allows cybercriminals to execute remote code on internal corporate networ…

Critical Zero-Day Flaw in Fortinet FortiWeb Allows Complete System Takeover

A severe pre-authentication SQL injection vulnerability in Fortinet's FortiWeb Fabric Connector has been discovered, allowing attackers to achiev…

ToolShell - Critical SharePoint Flaw Exposes to Unauthenticated Attacks

Microsoft has released emergency patches for two critical SharePoint vulnerabilities discovered at Pwn2Own Berlin, one of which allows completely una…

'Enter, Exit, Leak': New CPU Side-Channel Attacks Break Isolation in Modern Processors

Security researchers from Microsoft and ETH Zurich have uncovered four new speculative side-channel vulnerabilities in modern AMD and Intel processor…

Your Password Just Became Worthless: Why Hackers Are Winning the Authentication War

New research reveals threat actors are bypassing advanced security systems by targeting the weakest link: human credentials Cybercriminals have drama…

Critical CitrixBleed 2 Zero-Day Enables Memory Theft, Bypasses Authentication

A newly disclosed vulnerability in Citrix NetScaler appliances is allowing attackers to steal sensitive memory contents through a simple HTTP request…

Google Rushes to Fix Chrome's Fourth In-Wild Exploited Zero-Day - POC Released

Google has issued an emergency security update for Chrome to address a critical zero-day vulnerability that cybercriminals are actively exploiting in…

Critical Sudo Vulnerabilities Leads Root Access to Any Linux User

Two newly disclosed vulnerabilities in Sudo, the ubiquitous Linux privilege escalation tool, could allow virtually any local user to gain complete ad…

Catwatchful Android Spyware Exposes 62,000 Users Data

A critical SQL injection vulnerability has exposed the complete user database of Catwatchful, a sophisticated Android spyware operation that was secr…

Critical Zero-Day Vulnerability Grants Root Access to Wing FTP Servers Worldwide

A critical null-byte injection vulnerability in Wing FTP Server has been discovered that allows attackers to gain complete root access to affected sy…

CitrixBleed 2 Vulnerability Now Under Active Attack Worldwide

A critical new vulnerability dubbed " CitrixBleed 2 " is being actively exploited by cybercriminals, marking a dangerous return of sessio…

BreachForums Administrators Arrested - French Police Dismantled Cybercrime's Underground Empire

Global cybercrime marketplace suffers devastating blow as French authorities capture the masterminds behind the world's largest stolen data tradi…

CoinTelegraph Allegedly Hacked as Fake Crypto Airdrop Scam Targets Users

Major cryptocurrency news outlet Cointelegraph allegedly fell victim to a sophisticated website compromise, with attackers injecting malicious pop-up…

CoinMarketCap Hacked, Fake Pop-Ups Drain User Wallets

A major security breach at CoinMarketCap, a top cryptocurrency data platform, has exposed millions of users to a wallet-draining scam, raising fresh …

16 Billion Passwords Leaked in Largest Data Breach Ever—That's Two Accounts for Every Human Alive

A staggering 16 billion login credentials have been exposed in what security researchers are calling one of the largest data breaches in history, rep…

Russian Hackers Perfect New Social Engineering Attack That Bypasses MFA

Russian government-linked hackers have developed a sophisticated new social engineering technique that successfully bypasses multi-factor authenticat…

TokenBreak Attack - Single Character Bypass Defeats LLM Safety Guardrails

A single character change can now completely bypass the safety systems of major AI platforms like ChatGPT, Claude, and Gemini.  Security researchers …