Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered significant vulnerabilities in the firmware of Xiaomi’s popular Redmi Buds series, specifically affecting models ranging from the Redmi Buds 3 Pro up to the latest Redmi Buds 6 Pro. The discovery highlights critical flaws in the …

BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in ServiceNow’s Virtual Agent API and the Now Assist AI Agents application has been discovered, allowing unauthenticated attackers to impersonate any user and execute privileged AI agents remotely. Security researcher Aaron Costello from AppOmni disclosed the flaw, …

Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band emergency update to resolve a critical issue affecting Remote Desktop connections on Windows client devices. The problem emerged immediately following the installation of the January 2026 security update, identified as KB5074109. Administrators and users reported …

Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent message: organizations must immediately migrate away from Net-NTLMv1, a deprecated …

Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing long-standing issues in certificate security. Short-lived certificates last just 160 …

Argus – Python-powered Toolkit for Information Gathering and Reconnaissance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Argus is a comprehensive Python-based toolkit designed for reconnaissance tasks in cybersecurity. The developers recently released version 2.0, expanding it to include 135 modules. This tool consolidates network analysis, web app scanning, and threat intelligence into one interface. Users access …

Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Vertex AI contains default configurations that allow low-privileged users to escalate privileges by hijacking Service Agent roles. XM Cyber researchers identified two attack vectors in the Vertex AI Agent Engine and Ray on Vertex AI, which Google deemed “working …

Researchers Gain Access to StealC Malware Command-and-Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor’s identity through their own stolen session cookies. The breach highlights critical security failures in criminal operations built around credential …

Windows 11 PCs Fail to Shut Down After January Security Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s January 13, 2026, security update for Windows 11 has triggered a frustrating bug: affected PCs refuse to shut down or hibernate, instead restarting. The issue is caused by KB5073455, which targets OS Build 22621.6491 on Windows 11 version 23H2. …

Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare positions …