CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited …

Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, …

Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the …

Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns excitement around game footage …

Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that Enterprise-managed authorization is now generally available. The update expands support …

Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download …

Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The flaws could allow nearby attackers to run arbitrary commands …

Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide. The …

Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands …

Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams will soon let administrators automatically block identified …