Windows 11 New Security Feature Denies Unauthorized Access to System Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has introduced a significant security control in the latest Windows 11 preview update designed to restrict unauthorized interaction with critical system files. Released as part of the January 2026 non-security preview (KB5074105), this enhancement specifically targets the Storage settings …

1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in OpenClaw, the open-source AI personal assistant trusted by over 100,000 developers, has been discovered and weaponized into a devastating one-click remote code execution exploit. Security researchers at depthfirst General Security Intelligence uncovered a logic flaw that, …

State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic …

Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. …

Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million “users.” Researchers revealed …

AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional PDF reports while emphasizing safe, non-destructive testing. AutoPentestX targets Kali …

SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and …

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules …

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims …

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security discovery reveals that approximately 175,000 Ollama servers remain publicly accessible across the internet, creating a serious risk for widespread code execution and unauthorized access to external systems. Ollama, an open-source framework designed to run artificial intelligence models …