Hackers Exploiting Ivanti EPMM Devices to Deploy Dormant Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti EPMM Devices Exploited Hackers are actively exploiting Ivanti Endpoint Manager Mobile (EPMM) appliances to plant “dormant” backdoors that can sit unused for days or weeks. Ivanti recently disclosed two critical EPMM flaws, CVE-2026-1281 and CVE-2026-1340, spanning authentication bypass and …

Criminal IP Integrates with IBM QRadar to Deliver Real-Time Threat Intelligence Across SIEM and SOAR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States / California, February 9th, 2026, CyberNewswire Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface intelligence platform, is now integrated with IBM QRadar SIEM and QRadar SOAR. The integration brings external, IP-based threat intelligence directly into …

Discord to Age-Restrict User Access to Key Features Starting Next Month

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Discord Age-Restrict User Access Discord announced it will begin globally rolling out “teen-by-default” safety controls and an expanded “age assurance” system in early March, introducing clearer boundaries around age-restricted experiences while leaving most everyday use unchanged. The company says the …

Critical 0-Click RCE Vulnerability in Claude Desktop Extensions Exposes 10,000+ Users to Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Desktop Extensions 0-Click Vulnerability A new critical vulnerability discovered by security research firm LayerX has exposed a fundamental architectural flaw in how Large Language Models (LLMs) handle trust boundaries. The zero-click remote code execution (RCE) flaw in Claude Desktop …

Microsoft Exchange Online Flags Customers Legitimate Email as Phishing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Exchange Online Flags Legitimate Email Microsoft Exchange Online is experiencing a service degradation that incorrectly flags legitimate customer emails as phishing, quarantining them and disrupting communications. The issue, identified as EX1227432, started on February 5, 2026, at 10:31 AM …

Hackers Exploit Legitimate Apple and PayPal Invoice Emails in DKIM Replay Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity threats are swiftly evolving beyond easily spotted, poorly written phishing emails to sophisticated methods that leverage trusted digital infrastructure. Attackers are now exploiting legitimate business workflows within widely used platforms, effectively turning reputable services into unwitting accomplices for financial …

Roundcube Webmail Vulnerability Let Attackers Track Email Opens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Roundcube Webmail Vulnerability Roundcube, one of the world’s most popular open-source webmail solutions, has released critical security updates to address a privacy bypass vulnerability. The flaw detailed by NULL CATHEDRAL allowed attackers to load remote images and track email opens, …

New Node.js Based LTX Stealer Attack Users to Exfiltrate Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware strain dubbed “LTX Stealer” has emerged in the cyber threat landscape, utilizing a unique Node.js-based architecture to compromise Windows systems. First surfacing in early 2026, this malicious tool is designed to harvest sensitive user information, including …

European Commission Contains Cyber-Attack Targeting Staff Mobile Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

European Commission Cyber-Attack The European Commission has confirmed the detection and containment of a security incident affecting the central infrastructure that manages staff mobile devices. The breach, identified on January 30 through internal telemetry, resulted in unauthorized access to a …

Hackers Exploiting ClawHub Skills to Bypass VirusTotal Detections via Social Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have significantly evolved their attack strategies recently observed within the ClawHub ecosystem, moving away from easily detectable methods to more subtle techniques. Rather than embedding malicious payloads directly into files, they now host these dangers on convincing external …