OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in the GSSAPI Key Exchange patch was applied by numerous Linux distributions on top of their OpenSSH packages. The flaw, tracked as CVE-2026-3497, was uncovered by security researcher Jeremy Brown. It allows an attacker to crash SSH …

Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta Launches New Anti-Scam Tools on WhatsApp Facebook and Messenger Meta has launched a suite of advanced anti-scam tools across WhatsApp, Facebook, and Messenger to combat the growing industrialization of online fraud. These new defenses combine artificial intelligence, behavioral alerts, …

Attackers Hijack Microsoft 365 Accounts Through OAuth Device Code Abuse Without Stealing Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Analysts at ANY.RUN has identified a sharp spike in phishing campaigns exploiting Microsoft’s OAuth Device Authorization Grant flow, with more than 180 malicious URLs detected within a single week. Unlike conventional credential harvesting, this technique routes victims through legitimate Microsoft …

Critical MediaTek Vulnerability Lets Attackers Steal Android Phone PINs in 45 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the MediaTek Dimensity 7300 chipset allows a physical attacker to extract device PINs, decrypt on-device storage, and steal cryptocurrency wallet seed phrases in approximately 45 seconds, raising serious alarms for the roughly 25% of Android users …

Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI assistants have rapidly transformed daily operations, streamlining tasks for teams managing overloaded inboxes, client communications, and incident response. Tools like Microsoft Copilot integrate directly into daily workflows, summarizing emails and meetings while pulling context from across the Microsoft 365 …

Paloalto Cortex XDR Broker Vulnerability Attackers to Obtain and Modify Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paloalto Cortex XDR Broker Vulnerability A security advisory has been issued for a newly discovered vulnerability affecting the Cortex XDR Broker Virtual Machine (VM). This flaw could allow a highly privileged, authenticated attacker to access and alter sensitive system information. …

Ericsson US Discloses Data Breach – Hackers Stolen Employees and Customers Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ericsson Data Breach The U.S. subsidiary of a Swedish telecommunications multinational has disclosed a data breach exposing the personal information of employees and customers. The incident did not occur on Ericsson’s internal network, but rather targeted one of the company’s …

Cisco IOS XR Software Vulnerability Allow Attacker to Execute Commands as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

cisco-ios-xr-software-vulnerability Cisco has issued a high-severity security advisory warning organizations about two critical privilege-escalation vulnerabilities in its IOS XR Software. If exploited, these flaws could allow an authenticated, local attacker to execute arbitrary commands as root or gain full administrative …

Splunk RCE Vulnerability Allows Attackers to Execute Arbitrary Shell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk RCE Vulnerability A critical security advisory has been released, warning users of a high-severity vulnerability affecting both Enterprise and Cloud platforms. Tracked as CVE-2026-20163, this flaw carries a CVSS score of 8.0. It enables attackers to perform Remote Command …

SolarWinds Web Help Desk Deserialization Vulnerability Enables Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity authorities have flagged a severe security flaw in SolarWinds Web Help Desk that requires immediate attention from system administrators. Tracked as CVE-2025-26399, this vulnerability allows malicious actors to execute unauthorized commands directly on the host machine. Because of its …