Critical n8n Vulnerabilities Expose Automation Nodes to Full RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A fresh set of critical vulnerabilities in the popular workflow automation platform n8n is raising serious security concerns, as researchers warn that attackers could chain multiple flaws to achieve full remote code execution (RCE) on affected systems. …

Linus Torvalds Says AI Bug Reports Have Made Linux Security Mailing List Unmanageable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Linus Torvalds has warned that a “continued flood” of AI‑generated bug reports is making the Linux security mailing list “almost entirely unmanageable.” The project is now tightening rules on how AI‑found issues should be reported and handled. In …

Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Four malicious npm packages capable of stealing SSH keys, cloud credentials, cryptocurrency wallets, and environment variables, while one variant quietly transforms infected machines into a DDoS botnet. The campaign appears to be the work of a single …

CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on-premises email infrastructure. The flaw CVE-2026-42897 is a cross-site scripting …

1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used WordPress plugin powering over one million websites has been hit by two serious vulnerabilities that could allow attackers to steal sensitive data and access server files. Security researchers warn that the flaws in the Avada Builder plugin could …

Microsoft Confirms Windows 11 Update Fails With Error 0x800f0922

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a critical installation failure affecting its May 2026 Patch Tuesday cumulative update for Windows 11, KB5089549, leaving users stranded with error code 0x800f0922 and, in some cases, additional errors 0x80240069 and 0x80240031. The known issue was …

New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A critical Windows privilege escalation zero-day vulnerability dubbed “MiniPlasma” has emerged with a public proof-of-concept exploit that allows attackers to achieve SYSTEM-level privileges on fully patched Windows systems. Security researcher Nightmare-Eclipse released the weaponized exploit on GitHub …

Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 A critical vulnerability in a widely used WordPress plugin has exposed over 200,000 websites to full account takeover, raising urgent concerns across the security community. Discovered on May 8, 2026, by Wordfence’s AI-powered PRISM threat intelligence platform, …

Fast16 Malware Manipulated Nuclear Weapons Simulation Data to Sabotage Test Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 18, 2026 Fast16 malware has been reclassified as a precision tool engineered not to disrupt nuclear warheads directly, but to quietly falsify the outcome of nuclear weapons test simulations and stall weapons development. Rather than causing kinetic damage, Fast16’s …

Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 17, 2026 A threat actor infiltrated Grafana Labs’ GitHub environment, stealing a privileged token to download the company’s private codebase, and then attempted to extort the open-source observability giant with an unanswered ransom demand. Grafana Labs disclosed on May …