Vim Modeline Bypass Vulnerability Let Attackers Execute Arbitrary OS Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered high-severity vulnerability in the popular Vim text editor exposes users to arbitrary command execution on the operating system. Tracked as CVE-2026-34982, the flaw relies on a modeline sandbox bypass that triggers when a victim opens a specially …

Public PoC Exploit Released for Nginx-UI Backup Restore Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been disclosed in the Nginx-UI backup restore mechanism, tracked as CVE-2026-33026. This vulnerability allows threat actors to tamper with encrypted backup archives and inject malicious configurations during the restoration process. With a public Proof-of-Concept (PoC) …

Microsoft to Remove EXIF Data for Images Shared on Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant move to enhance corporate privacy and operational security, Microsoft has announced an important update for its Teams platform. As part of the March 2026 feature rollout, Microsoft Teams will now automatically remove EXIF metadata from all images …

Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Magecart Hijacks eStore Checkouts to Steal Card Data A sophisticated and long-running Magecart campaign has been quietly operating for over 24 months, infecting e-commerce websites across at least 12 countries using more than 100 malicious domains to steal payment card …

Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence agents are rapidly becoming integral to enterprise workflows, but they also introduce new attack surfaces. Security researchers recently uncovered a significant vulnerability within Google Cloud Platform’s Vertex AI Agent Engine. By exploiting default permission scoping, attackers could weaponize …

Hackers Actively Exploiting Critical WebLogic RCE Vulnerabilities in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent cybersecurity study reveals that threat actors are moving faster than ever to weaponize new software flaws. According to data collected from a high-interaction honeypot, hackers are actively exploiting a newly disclosed, maximum-severity vulnerability in Oracle WebLogic Server. The …

Russian Hackers Using Remote Access Toolkit “CTRL” for  RDP Hijacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed Russian-linked remote access toolkit called “CTRL” is being used to hijack Remote Desktop Protocol sessions and steal credentials from Windows systems. According to Censys ARC, the malware is a custom .NET framework that combines phishing, keylogging, reverse …

Hackers Hijack Hotel Booking Workflows to Scam Guests With Fake Payment Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Travelers across the world are being targeted by a fast-growing fraud scheme that turns their own hotel reservations against them. Cybercriminals are hijacking trusted hotel booking workflows to deliver convincing fake payment requests to guests — and many victims never …

Cisco Source Code and Data Leak Allegedly Claimed by ShinyHunters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal group ShinyHunters has allegedly claimed responsibility for three separate data breaches targeting Cisco Systems, Inc., asserting that over 3 million Salesforce records containing personally identifiable information (PII), GitHub repositories, AWS S3 buckets, and other sensitive internal corporate …

Windows 11 Emergency Update to Fix Installation Loop Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft just released an emergency out-of-band update to resolve a persistent installation failure affecting Windows 11 users. Released on March 31, 2026, update KB5086672 specifically targets systems running Windows 11 versions 25H2 and 24H2. This patch addresses a critical setup …