Critical Jenkins Vulnerabilities Expose CI/CD Servers to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins Vulnerabilities Expose CI/CD Servers A critical security advisory addressing multiple high-severity vulnerabilities in Jenkins core and the LoadNinja plugin. Issued on March 18, 2026, the alert warns that these flaws could allow attackers to execute arbitrary code and fully …

Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Navia Data Breach A prominent U.S. consumer-focused benefits administrator has disclosed a significant data breach exposing the sensitive personal and health information of approximately 2.7 million individuals.​ On January 23, 2026, Navia detected suspicious activity within its network environment. Following …

Bamboo Data Center and Server Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bamboo Data Center and Server Vulnerability A high-severity security flaw has been addressed in Bamboo Data Center, an enterprise platform widely used for software build and release management. Tracked as CVE-2026-21570, this Remote Code Execution (RCE) vulnerability allows authenticated threat …

New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered infostealer malware named Speagle has emerged as a serious threat targeting organizations that run Cobra DocGuard, a document security and encryption platform developed by Chinese company EsafeNet. The malware is engineered to blend into its host environment, …

Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apex AI Penetration Testing Agent Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, hints, or predefined attack paths. This enables it to discover, …

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on …

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive email data. Dubbed “Operation GhostMail,” the campaign stands out for …

Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities Disrupts IoT Botnet Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets. The U.S. Justice Department, collaborating closely with Canadian and German agencies, targeted the administrators and architecture behind the Aisuru, KimWolf, …

CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Zimbra Collaboration Suite Vulnerability Exploit CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. …

CISA Urges Organizations to Secure Microsoft Intune Environments Following Stryker Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert urging organizations to harden their endpoint management system configurations following a cyberattack on Stryker Corporation, a U.S.-based medical technology firm, on March 11, 2026. The attack targeted …