Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Posts

YouTube Now Wants 8,000 Watch Hours for Monetisation

Most of the attention on YouTube's August 10 announcement went to the double-entry bar for newcomers. The change with longer teeth applies to the…

Microsoft Leaves Windows Passkey Prompt Spoofing Unfixed

Three weeks before Microsoft makes passkeys the default sign-in method for Entra ID , new research shows that the Windows dialog protecting them can …

Windows 11 Kernel 0day PoC Drops Before Patch Tuesday

An anonymous researcher has published proof-of-concept (PoC) code for what they describe as an unpatched local privilege-escalation flaw in Windows 1…

DeadLock Ransomware Puts Its Negotiation Portal On-Chain

Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one. Microsoft Threat Intelligence ha…

Researchers Buy 'No Reply' Domains and Get Company Data

Fifteen dollars is roughly what it costs to start reading email your company thinks nobody receives. Two security researchers who quietly bought plac…

Metabase Zero-Day Exposes Framework, Tally Customer Data

Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the an…

Public Exploit Lands for WordPress XSS2Shell Core Flaw

A working proof-of-concept exploit for " XSS2Shell " is now circulating publicly, raising the stakes on a WordPress Core flaw that turns a …

Meta AI Breach Turns Spotlight on Testing Firm Irregular

Meta confirmed on Wednesday that one of its AI models reached the open internet and hacked a third-party service during a security evaluation. It is …

Zapscape KVM Flaw Lets Guest VMs Seize Host Root

Security researcher Hyunwoo Kim closed out his KVM escape trilogy today with Zapscape (CVE-2026-64561) , and this time he shipped the whole thing.  W…

The New Attack Surface: How Cybercriminals Are Using AI to Target Developers

Cybercriminals are increasingly targeting developers in attacks. One of the major factors behind the trend is access. Developers often work on a wide…

Mac Malware Checks Your GPU Before Showing Its Lure

The crews behind a long-running macOS scam have started doing something defenders usually do: vetting who is on the other end of a connection before …

Researchers Chain WordPress RCE to Fileless Linux Root

Security researchers have shown that the critical wp2shell WordPress flaw doesn't have to stop at a web shell — it can be chained all the way to…

Blogger's Malware Glitch: Don't Touch Your Template

If your Blogger blog was locked for "Malware and Similar Malicious Content" and has since come back, read this before you touch anything: d…

Gmail to End "Send As" for Outlook and Yahoo Addresses

Google has put a date on the retirement of one of Gmail's oldest power-user features. Starting January 2027, the "Send as" option that …

Human Reviewer Caught AI Agent's Malware Pull Request

The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was o…

Phishers Abuse Service Workers to Hijack Microsoft Logins

A phishing campaign documented by Kaspersky turns an ordinary browser feature into a credential-stealing proxy, letting attackers walk away with Micr…