Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in LangChain’s core library (CVE-2025-68664) allows attackers to exfiltrate sensitive environment variables and potentially execute code through deserialization flaws. Discovered by a Cyata researcher and patched just …

100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As artificial intelligence becomes deeply embedded in enterprise operations and cybercriminal arsenals alike, the Cybersecurity Predictions 2026 landscape reveals an unprecedented convergence of autonomous threats, identity-centric attacks, and accelerated digital transformation risks. …

Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as CVE-2025-68615, this security flaw allows remote attackers to trigger …

Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and potentially granting unauthorized access to VPNs and admin consoles. Fortinet’s …

Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced hardware-accelerated BitLocker, a significant security enhancement designed to eliminate performance bottlenecks caused by encryption on modern high-speed NVMe drives. The new technology addresses growing concerns about CPU …

Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November 2022, using advanced techniques to deliver the MgBot malware. The …

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to look like legitimate security tools. The attacks began in November …

Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software and endpoint detection tools. The tool was posted on an …