New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new generation of phishing kits designed specifically for voice-based attacks has emerged as a growing threat to enterprise users across major technology platforms. Okta Threat Intelligence discovered multiple custom phishing kits available on an as-a-service basis that criminals …

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js has updated its HackerOne vulnerability disclosure program to require a minimum Signal score of 1.0, aiming to reduce low-quality submissions and improve processing efficiency. Node.js has implemented a new threshold for vulnerability report submissions through its HackerOne program, mandating …

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security feature for Teams Calling now alerts users to suspicious external calls that try to impersonate trusted organizations. The feature will begin deployment in mid-February 2026 for Targeted Release customers, with general availability timelines to be communicated later. …

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass vulnerability, with a new automated campaign targeting even fully patched FortiGate devices. Cybersecurity firm Arctic Wolf first observed the attacks on January 15, 2026, involving rapid configuration exfiltration and persistence …

New Windows Notepad and Paint Update Brings More Useful AI Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence (AI) features have been added to Windows 11 Notepad and Paint for Canary and Dev Channel users, turning them into cloud-connected tools that require sign-in. The Notepad update (version 11.2512.10.0) brings AI-powered text generation, rewriting, and summarization features …

TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TrustAsia has revoked 143 SSL/TLS certificates following the discovery of a vulnerability in its LiteSSL ACME service. The flaw allowed for the improper reuse of domain validation data across different ACME accounts, prompting an immediate suspension of issuance services and …

HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability affecting multiple storage platforms could allow remote attackers to gain administrative access without physical interaction. The flaw, tracked as CVE-2026-23594, impacts HPE Alletra 6000, Alletra 5000, and Nimble Storage arrays running vulnerable firmware versions. The …

North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea–aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. …

Nike Allegedly Hacked by WorldLeaks Ransomware Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Athletic footwear and apparel manufacturer Nike has become the latest victim of WorldLeaks, a financially motivated ransomware group known for data extortion attacks. The group announced the breach on its darknet leak site on January 22, claiming responsibility for the …

New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s January 2026 Windows 11 security update KB5074109 has triggered multiple system stability issues, including lockups and black screens, prompting users to uninstall it. Reports highlight graphics regressions and app failures affecting both consumer and enterprise setups. KB5074109 targets Windows …