Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a …

PraisonAI Vulnerability Exploited Within Hours of Public Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. Within hours of public disclosure, a severe vulnerability in PraisonAI’s …

Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A critical vulnerability in the Amazon Redshift JDBC driver has put enterprise applications at severe risk of Remote Code Execution (RCE). Threat actors can exploit this newly disclosed flaw simply by manipulating database connection URLs. This hidden …

Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A nation-state malware known as Kazuar has resurfaced with a far more dangerous design than anyone expected. What once started as a relatively standard backdoor has now grown into a fully modular, peer-to-peer botnet specifically engineered for …

VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and …

Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A state-aligned hacking group known as FrostyNeighbor has resurfaced with a fresh wave of cyberattacks targeting government organizations in Ukraine, using a carefully designed infection chain that is harder than ever to detect. The group, active since …

OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 Two employee devices at OpenAI were compromised in a sweeping software supply chain attack targeting TanStack npm, but the AI company confirmed no user data, production systems, or intellectual property were affected. On May 11, 2026 UTC, …

Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited in the wild, allowing unauthenticated remote attackers to fully bypass authentication and seize administrative control of enterprise network infrastructure. Tracked as CVE-2026-20182 with a …

Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Russian state-sponsored hacking group known as Sandworm has been caught making a calculated pivot from compromised IT networks into operational technology systems that control physical infrastructure. The campaign is alarming because it does not rely on …

Chinese APT Hackers Exploit Microsoft Exchange to Breach Energy Sector Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Chinese state-linked hacking group known as FamousSparrow has quietly infiltrated an Azerbaijani oil and gas company, exploiting an unpatched Microsoft Exchange server to plant multiple backdoors inside the network. The attack ran from late December 2025 …