IDrive for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical local privilege escalation vulnerability has been identified in the IDrive Cloud Backup Client for Windows. Tracked as CVE-2026-1995, this local privilege escalation vulnerability affects the IDrive Cloud Backup Client for Windows, specifically targeting versions 7.0.0.63 and earlier. Security researchers …

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Malware-as-a-Service (MaaS) credential stealer named Torg Grabber has surfaced, showing remarkable development pace over just three months. Starting with simple Telegram-based data exfiltration, it matured into a fully encrypted REST API command-and-control (C2) infrastructure. With 334 samples compiled …

Fake Screenshot Lures Used to Infect Web3 Support Staff With Multi-Stage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat group known as APT-Q-27 has been running an active campaign against Web3 customer support teams, using fake screenshot links in live chat windows to silently install a persistent backdoor on victim machines. The attack targets the most human …

Silver Fox Abuses Stolen EV Certificates in AtlasCross RAT Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese-nexus advanced persistent threat group Silver Fox, also tracked as Void Arachne and SwimSnake, is actively targeting Chinese-speaking users and professionals with a sophisticated AtlasCross RAT campaign. Security researcher Maurice Fielenbach of Hexastrike found that threat actors leveraging typosquatted …

Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory has been issued for a severe vulnerability in DiskStation Manager (DSM) that allows unauthenticated remote attackers to execute arbitrary commands. Given the widespread use of Synology network-attached storage (NAS) systems for enterprise backups and data management, …

Cisco Secure Firewall Vulnerability Allows Remote Code Execution as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has released an urgent security advisory addressing a critical vulnerability in its Secure Firewall Management Center (FMC) software. This severe flaw allows unauthenticated remote attackers to execute arbitrary code with full root privileges. CVE-2026-20131 is a critical vulnerability with …

Microsoft Entra ID New Feature Removes MFA Limitations for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multifactor authentication operates as a critical defense mechanism for securing user identities against targeted cyber attacks. Microsoft reports that implementing MFA effectively reduces the risk of account compromise by more than 99%. To expand these protections, Microsoft has announced the …

OpenAI Launches AI Safety Bug Bounty to Detect AI-Specific Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has announced the launch of a public Safety Bug Bounty program to identify AI abuse and safety risks across its products. Hosted on Bugcrowd, the new initiative marks a significant step in the company’s efforts to address vulnerabilities that …

New Kiss Loader Malware Uses Early Bird APC Injection in Emerging Attack Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware loader called Kiss Loader has emerged as a serious threat, using advanced code injection techniques to quietly infiltrate Windows systems without raising alarms. First spotted in early March 2026, it marks the beginning of a carefully …

Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and carefully crafted software supply chain campaign is targeting developers through the npm package registry, using fake installation messages to hide malicious activity. The campaign, which security researchers have named the “Ghost campaign,” began in early February 2026 …