Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A set of nine novel cross-tenant vulnerabilities in Google Looker Studio, collectively dubbed “LeakyLooker,” that could have allowed attackers to run arbitrary SQL queries, exfiltrate sensitive data, and even modify or delete records across Google Cloud environments, all without victims …

Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 and Server 2025 Automated Installation Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, …

Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has confirmed it will permanently remove end-to-end encryption (E2EE) support from Instagram direct messages, with the feature officially shutting down after May 8, 2026. The announcement, quietly posted on Instagram’s Help Center support page, marks a significant reversal from …

Microsoft Releases Out-of-Band Patch to Fix Critical RRAS RCE Vulnerabilities in Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and 26100.7982, this update patches three actively concerning flaws in the …

FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A series of intrusions in early 2026 in which threat actors compromised FortiGate Next-Generation Firewalls (NGFW) to establish persistent footholds within enterprise environments. Each case was intercepted during the lateral movement phase before the attackers could fully achieve their objectives. …

Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious npm Packages Target Discord Crypto Wallets JFrog security researchers Guy Korolevski and Meitar Palas uncovered a sophisticated supply chain attack on the npm ecosystem on March 12, 2026, in which threat actors disguised an information-stealing malware as a legitimate …

GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GlassWorm 72 Malicious Open VSX Extensions In a major escalation of supply chain attacks, the GlassWorm malware campaign has evolved to infect developer environments using transitive dependencies. On March 13, 2026, the Socket Research Team reported identifying at least 72 …

Critical LangSmith Account Takeover Vulnerability Puts Users at Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical LangSmith Account Takeover Vulnerability Miggo Security researchers have identified a critical vulnerability in LangSmith, tracked as CVE-2026-25750, that exposes users to potential token theft and complete account takeover. As a central hub for debugging and monitoring large language model …

Authorities Crack Down on 45,000 Malicious IPs Powering Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities Crack Down on 45000 Malicious IPs In a massive international crackdown on cybercrime, law enforcement agencies from 72 countries have successfully dismantled over 45,000 malicious IP addresses and servers. Coordinated by INTERPOL, “Operation Synergia III” targeted the critical infrastructure …

Microsoft Confirms Windows 11 24H2/25H2 Bug Blocks Access to the System Drive C

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a critical bug affecting Windows 11 users on certain Samsung devices, in which the system drive (C:) becomes completely inaccessible after installing the February 2026 security update. The company is now actively investigating the issue in …