OpenAI Launches GPT-5.4 with Reverse Engineering, Vulnerability and Malware Analysis Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled GPT-5.4-Cyber, a specialized variant of its flagship GPT-5.4 model fine-tuned for advanced defensive cybersecurity workflows, granting vetted security professionals expanded access to capabilities such as binary reverse engineering, vulnerability scanning, and malware analysis, with fewer restrictions than …

Microsoft SharePoint Server 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day spoofing vulnerability in Microsoft SharePoint Server is being actively exploited in the wild, Microsoft confirmed on April 14, 2026, as part of its monthly security update cycle. Tracked as CVE-2026-32201, the flaw affects multiple versions of SharePoint …

Security Risk Advisors Purple Team Participants Can Now Earn CPE Credits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Philadelphia, United States / Pennsylvania, April 14th, 2026, CyberNewswire GIAC and ISC2 now recognize active participation in SRA Purple Team exercises as an eligible Continuing Professional Education (CPE) activity. Teams can earn CPE credits while strengthening organizational detection and response capabilities! How? Some CPE activities …

Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet released a sweeping batch of security advisories on April 14, 2026, addressing 11 vulnerabilities spanning multiple product lines, including two rated Critical, two rated High, and seven rated Medium or Low. The disclosures affect FortiSandbox, FortiAnalyzer, FortiManager, FortiOS, FortiProxy, …

Critical etcd Auth Bypass Flaw Allows Unauthorized Access to Sensitive Cluster APIs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability has emerged in etcd, the foundational distributed key-value store that supports countless cloud-native systems and Kubernetes clusters globally. Tracked as CVE-2026-33413, this high-severity flaw carries a CVSS score of 8.8. It enables attackers to access …

Ivanti Neurons for ITSM Vulnerabilities Allow Remote Attacker to Obtain User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has released security updates addressing two medium-severity vulnerabilities in Ivanti Neurons for ITSM (N-ITSM), its on-premise IT service management platform. The flaws, if exploited, could allow remote authenticated attackers to retain unauthorized access or harvest session data from other …

CISA Warns of Microsoft Exchange and Windows CLFS Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to organizations regarding two severe Microsoft vulnerabilities. On April 13, 2026, the agency officially added flaws affecting Microsoft Exchange Server and the Windows Common Log File System (CLFS) …

New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Android malware called Mirax has been quietly circulating in underground criminal forums since late 2025, posing a growing threat to mobile users across Europe and beyond. What sets it apart from typical banking trojans is its dual …

New PlugX USB Worm Spreads Across Multiple Continents Using DLL Sideloading

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered variant of the PlugX worm is silently crossing borders by hiding inside USB drives, and it has already been detected on multiple continents spanning nearly ten time zones. First spotted in Papua New Guinea in August 2022, …

Hackers Leave Credential Stuffing Botnet Wide Open With Full Worker Access and Root Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A live credential stuffing botnet targeting Twitter/X accounts has been found completely exposed to the internet, with no password required to access its control panel, worker server credentials, or real-time attack data. The exposed system, running under the name “Twitter …