generalnews.media
All World Business Technology Science Health Sports Entertainment Security
67 stories
security technology

WebKit Flaw Leaks IP and DNS Data in Proxy Browsers, iCloud Private Relay

A vulnerability in Apple's WebKit engine can expose users' real IP addresses and DNS queries, bypassing proxy protections in browsers and iCloud Private Relay. This undermines privacy tools meant to hide user location and activity. Users should apply security updates to mitigate the leak.

Exclusive

Greatness PhaaS Kit Adds Device Code Phishing to Bypass MFA

The Greatness phishing-as-a-service platform has added a device code phishing technique that bypasses multi-factor authentication and steals access tokens. This method tricks users into submitting codes on attacker-controlled devices, allowing session hijacking even with MFA enabled. Organizations should update training and monitoring to address this evolving threat.

Exclusive

Fake Adobe and Zoom Updates Deliver ScreenConnect Backdoor

Cybercriminals are tricking users with fake Adobe and Zoom update prompts that install ScreenConnect, a legitimate remote access tool, granting persistent control of infected systems. This enables attackers to maintain long-term access and potentially steal data or deploy further malware. Users should only download updates from official sources to avoid this threat.

Exclusive

'Vibe Hacking' Turns AI Into a Powerful Tool for Cyberattackers

Cybercriminals are exploiting "vibe hacking"—a casual, conversational approach to programming AI—to quickly generate effective attack code. This trend lowers the technical barrier for adversaries, making AI a more accessible and dangerous weapon for launching cyberattacks.

Exclusive

Google Pulls 3 AI Agent Workflows Over Privilege Escalation Risk

Google removed three Agent Development Kit (ADK) workflows after discovering a malicious GitHub issue could potentially trigger a privileged agent. The flaw could have allowed unauthorized actions in the AI agent environment. The takedown highlights security concerns in AI-powered workflow automation.

Exclusive

Google Can Search Some Claude AI Chat Conversations

Security researchers have found that some conversations from Anthropic's Claude AI chatbot are appearing in Google search results. These chats were likely shared via public links and indexed, raising privacy and data exposure concerns.

Exclusive

New DOUBLECUP Attack Uses ClickFix and PNGs to Spread RATs

The DOUBLECUP campaign employs ClickFix social engineering and cached PNG images to deliver CountLoader and DeviceManager remote access trojans. The malware gives attackers remote control and data theft capabilities, highlighting a growing evasion trend. Users should exercise caution with unsolicited links and file downloads.

Exclusive

Weekly Security Recap: Rogue AI, $88M Bitcoin Theft, Water Attacks, DNS Hijacks

This week's cybersecurity roundup covers malicious AI models, an $88 million Bitcoin theft, attacks on water systems, and hijacked dormant DNS domains. These incidents highlight evolving threats targeting critical infrastructure and digital assets. The recap is essential for security teams tracking emerging vulnerabilities.

security world

Michigan and Minnesota report cyberattacks; FBI investigates

Michigan has joined Minnesota in disclosing cyberattacks as authorities investigate potential security breaches. The FBI is looking into the incidents, which affect state government systems and raise concerns about election and infrastructure security.