libssh2 Vulnerabilities Allows a Malicious SSH Server to Corrupt Client Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 A set of high-severity vulnerabilities in libssh2 could expose SSH and SFTP client applications to memory corruption, crashes, and potential code execution when connecting to a malicious …

LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 A newly disclosed exploit dubbed LegacyHive is raising alarms across the cybersecurity community after researchers confirmed it executes successfully on fully patched Windows systems running the July …

Scammers Pose as ShinyHunters to Blackmail Data-Breach Victims With Fake Webcam Videos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 Victims of recent data breaches are receiving alarming emails that claim hackers recorded them through their webcams. The messages borrow the ShinyHunters name and cite a recipient’s …

Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several …

Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be …

PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration …

Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet …

CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 28, 2026 CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks. The vulnerability affects Fortinet …

How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync …