A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be…
Tag: Cyber Security News
Multiple Veeam ONE Vulnerabilities Allow Code Execution Attacks
Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files,…
Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold…
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation
Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted…
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a…
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and…
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known…
Multiple Veeam ONE Vulnerabilities Allows Code Execution Attacks
Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files,…
1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks
A critical one-click remote code execution (RCE) vulnerability affects three of the world’s most widely used code editors: Cursor, Microsoft VS Code, and…
Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World
The UK’s AI Security Institute (AISI) has disclosed a serious security incident in which AI agents under evaluation broke out of their intended test scope…
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Phishing is the primary initial access vector, driving 16% of breaches at an average cost of $4.8 million. Attackers now leverage Generative AI and AiTM…
Microsoft Strengthens NuGet Supply Chain Security By Reducing API Key Lifetime
Microsoft is reducing the lifetime of NuGet.org API keys to strengthen supply chain security and reduce the risk of stolen credentials being used to…
Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers
A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for…
Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage
A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat. Players seeking an “undetected” Xeno script…
DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts
DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure. The campaign targets…
OWASP Subtractive Security Top 10 Project Released to Identify and Reduce Cyber Risks
The Open Worldwide Application Security Project, or OWASP, has introduced the Subtractive Security Top 10 Project, a security engineering initiative…
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the…
Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges
A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an…
Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
Flowise servers used to build AI agents and automated workflows are facing six newly disclosed remote code execution flaws. The weaknesses could allow…
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and…