Threat Actors Abuse Microsoft & Google Platforms to Attack Enterprise Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Enterprise security teams are facing a sophisticated new challenge as cybercriminals increasingly exploit trusted cloud platforms to launch phishing attacks. Instead of relying on suspicious newly registered domains, threat actors now host their malicious infrastructure on legitimate services like Microsoft …

CISA Warns of GitLab Community and Enterprise Editions SSRF Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns GitLab SSRF Vulnerability Exploit A critical GitLab vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog. Threat actors are actively exploiting a server-side request forgery (SSRF) flaw in GitLab Community and Enterprise editions. The vulnerability, tracked …

Hackers Using AI to Get AWS Admin Access Within 10 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AWS Admin Access in Minutes Threat actors leveraging artificial intelligence tools have compressed the cloud attack lifecycle from hours to mere minutes, according to new findings from the Sysdig Threat Research Team (TRT). In a November 2025 incident, adversaries escalated …

One Identity Appoints Gihan Munasinghe as Chief Technology Officer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Alisa Viejo, United States, February 4th, 2026, CyberNewsWire One Identity, a leader in unified identity security, today announced the appointment of Gihan Munasinghe as Chief Technology Officer. Munasinghe brings more than 15 years of experience leading global engineering organizations and delivering …

Hackers Exfiltrating NTDS.dit File to Gain Full Active Directory Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Active Directory remains the backbone of enterprise authentication systems, storing critical information about user accounts, passwords, and domain configurations. Recently, security experts have observed a surge in attacks targeting the NTDS.dit database file, which contains encrypted password hashes for every …

Hackers Actively Scanning Citrix NetScaler Infrastructure to Discover Login Panels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected between January 28 and February 2, 2026, by the GreyNoise Global Observation Grid. The coordinated operation combined residential proxy rotation for login panel discovery with concentrated …

Ingress-Nginx Vulnerability Allow Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ingress-Nginx Vulnerability A critical security vulnerability has been discovered in ingress-nginx, a popular Kubernetes ingress controller, that could allow authenticated attackers to execute arbitrary code and access sensitive cluster secrets. The vulnerability, tracked as CVE-2026-24512, affects multiple versions of the software …

CISA Warns of SolarWinds Web Help Desk RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns SolarWinds Web Help Desk Vulnerability An urgent warning regarding a critical remote code execution (RCE) vulnerability in SolarWinds Web Help Desk. The vulnerability, tracked as CVE-2025-40551, exploits unsafe deserialization of untrusted data and could allow attackers to execute …

Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Vulnerabilities Arbitrary Code Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks. The update pushes the browser version to …

Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

React Server Vulnerability Exploited Two months following the disclosure of CVE-2025-55182, exploitation activity targeting React Server Components has evolved from broad scanning into consolidated, high-volume attack campaigns. According to telemetry from GreyNoise collected between January 26 and February 2, 2026, …