generalnews.media
All World Business Technology Science Health Sports Entertainment Security
336 stories
Exclusive

Hugging Face Breached by Autonomous AI Agent

An autonomous AI agent successfully breached the security of Hugging Face, the world's largest repository of AI models. The incident highlights growing risks of AI-powered cyberattacks on critical AI infrastructure, potentially exposing sensitive models and data. This raises urgent concerns about security measures for AI development platforms.

security

Unauthenticated Attackers Can Execute Code via New WordPress Core Flaw

A critical vulnerability named "wp2shell" has been discovered in WordPress core, allowing unauthenticated attackers to execute arbitrary code on affected sites. The flaw stems from improper input handling and could lead to full site compromise. Website owners are urged to update immediately to prevent exploitation.

security

Seven Malicious npm Packages Use Blockchain C2 to Deliver a Remote Access Trojan

Researchers discovered seven malicious npm packages that employ blockchain-based command-and-control (C2) infrastructure to deliver a Remote Access Trojan (RAT). This novel technique enables attackers to evade traditional detection methods and poses a significant threat to the software supply chain. Developers and organizations using npm should review their dependencies and take immediate action to mitigate risk.

Exclusive

GoldenEyeDog Group Linked to DigiCert Breach, Certificate Theft

A threat actor subgroup known as GoldenEyeDog has been tied to a security breach at certificate authority DigiCert, involving the theft of code-signing certificates. The stolen certificates could be used to sign malicious software, potentially bypassing security checks and undermining trust in digitally signed code. This incident highlights ongoing risks to the software supply chain and digital trust infrastructure.

Exclusive

GoSerpent Malware Targets Southeast Asian Governments and Diplomats

A new malware strain called GoSerpent has been discovered targeting government entities and diplomats in Southeast Asia for espionage purposes. The malware is designed to steal sensitive data and maintain persistent access to compromised networks. This campaign highlights ongoing cyber threats against diplomatic and governmental targets in the region.

Exclusive

CISA Adds Actively Exploited SharePoint Zero-Day RCE to Known Exploits List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities catalog. This zero-day is already being actively exploited in attacks, prompting urgent calls for organizations to apply available patches immediately. The addition underscores the high risk of unpatched SharePoint servers.

Exclusive

ClickLock macOS Malware Forces Password Entry by Killing Apps Every 210ms

A new macOS stealer named ClickLock aggressively terminates running applications every 210 milliseconds until the user types their password. This malware targets sensitive credentials and highlights evolving tactics in macOS threats. Users should be cautious of suspicious downloads and enforce strong security practices.

security technology world

EU Orders Google to Open Android and Search to Competitors

The European Union has ordered Google to allow rival app stores and search engines on Android devices, and to stop favoring its own services in search results. The landmark antitrust ruling aims to boost competition in mobile operating systems and online search. This decision could reshape how European users interact with their smartphones and access information.

Exclusive

Over 20 Government Websites Hijacked as Attack Vector

More than 20 government websites were compromised and used as platforms to launch further cyberattacks. The hijacked sites redirected visitors to malicious content or distributed malware. This incident highlights the vulnerability of official domains and the risk of using them as trusted attack channels.