Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: vulnerability

Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges

post, juli 18, 2026juli 20, 2026

A security weakness in Anthropic’s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce. The issue was discovered by Manifold…

Continue Reading

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

post, juli 17, 2026juli 20, 2026

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser…

Continue Reading

Zoom Patches Critical Flaw Allowing Remote Account Takeover

post, juli 16, 2026juli 17, 2026

Zoom has released emergency security updates to address a critical vulnerability in several of its Windows products that could allow an unauthenticated attacker to take control of a user’s account over a network. The vulnerability, tracked as CVE-2026-53412, affects the Zoom Workplace desktop application, the company’s Virtual Desktop Infrastructure client…

Continue Reading

Microsoft Fixes Record 600+ Vulnerabilities In July 2026 Patch Tuesday, Including Three Zero-Day Flaws

post, juli 15, 2026juli 17, 2026

Microsoft has released its July 2026 Patch Tuesday security updates, delivering fixes for a record-breaking 622 vulnerabilities across Windows, Microsoft Office, SharePoint, Azure-related components, Visual Studio, and other products. The release marks the largest Patch Tuesday update in the company’s history and includes patches for three zero-day vulnerabilities, two of…

Continue Reading

New macOS Malware Impersonates Apple’s Notarized Installer

post, juli 14, 2026juli 17, 2026

A newly identified macOS information-stealing malware family, dubbed CrashStealer, is raising concerns after leveraging an Apple-notarized installer to bypass one of macOS’s most important security protections. By abusing Apple’s trusted software signing and notarization process, the malware is able to execute without triggering the Gatekeeper security warnings that users typically…

Continue Reading

Accenture Confirms Security Breach Following Claims of Stolen Source Code

post, juli 8, 2026juli 17, 2026

One of the world’s largest technology consulting firms is investigating a security incident after a threat actor claimed to have stolen tens of gigabytes of internal development data allegedly belonging to Accenture. The individual, using the online alias “888,” has advertised what they describe as approximately 35GB of confidential company…

Continue Reading

Five Eyes Warns AI Models Capable of Devastating Cyber Attacks Are Only Months Away – Leaders Must Act Immediately

post, juni 24, 2026

AI-Driven Cyber Threats Accelerate Global Security Risks as Five Eyes Agencies Warn Leaders to Act Immediately. Intelligence alliance says artificial intelligence is reshaping the cyber battlefield at unprecedented speed, leaving organisations with only months—not years—to prepare The world’s leading cyber security agencies have issued a stark warning to business leaders…

Continue Reading

Anthropic’s Claude Mythos Reportedly Circumvents Apple Mac Security Systems

post, mei 17, 2026mei 18, 2026

Anthropic’s highly restricted cybersecurity AI is already helping researchers uncover dangerous vulnerabilities inside Apple’s software ecosystem, offering one of the clearest signs yet that artificial intelligence is rapidly transforming the future of cyber warfare, digital defense, and software exploitation. The AI model, known internally as Claude Mythos, has not been…

Continue Reading

Microsoft Warns of Active Exploitation Targeting On-Premises Exchange Servers Through Malicious Emails

post, mei 15, 2026mei 18, 2026

Security researchers and enterprise defenders are scrambling to respond after Microsoft disclosed that attackers are actively exploiting a newly discovered vulnerability in on-premises Microsoft Exchange Server deployments, potentially allowing threat actors to execute malicious scripts through specially crafted emails. The vulnerability, identified as CVE-2026-42897, carries a CVSS severity score of…

Continue Reading

Cisco Warns of Actively Exploited Critical SD-WAN Vulnerability Allowing Remote Administrative Access

post, mei 14, 2026mei 18, 2026

Cisco has issued an urgent security advisory after confirming that a critical authentication bypass vulnerability affecting its Catalyst SD-WAN infrastructure is being actively exploited in real-world attacks, prompting widespread concern across enterprise and government networks worldwide. The flaw, tracked as CVE-2026-20182, carries the maximum possible CVSS severity score of 10.0…

Continue Reading
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • …
  • 15
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes