Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has confirmed active exploitation of a critical zero-day remote code execution vulnerability in its Secure Email Gateway and Secure Email and Web Manager appliances. Tracked as CVE-2025-20393, the flaw allows unauthenticated attackers to execute arbitrary root-level commands via crafted …

Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google is gradually rolling out the ability to change the @gmail.com email address associated with a Google Account to a new @gmail.com address. This feature, previously unavailable, addresses a common pain point for users who regret their original username choice …

Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution risks, and TLS mishandlings that could expose developers to remote …

New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical misconfiguration in AWS CodeBuild enabled unauthenticated attackers to seize control of key AWS-owned GitHub repositories, including the widely used AWS JavaScript SDK powering the AWS Console itself. This supply chain vulnerability threatened platform-wide compromise, potentially injecting malicious code …

Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are increasingly using trusted cloud and content delivery network platforms to host phishing kits, creating major detection challenges for security teams. Unlike traditional phishing campaigns that rely on newly registered suspicious domains, these attacks use legitimate infrastructure from …

Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large language models have become deeply integrated into everyday business operations, from customer service chatbots to autonomous agents managing calendars, executing code, and handling financial transactions. This rapid expansion has created a critical security blind spot. Researchers have identified that …

Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet FortiSIEM vulnerability CVE-2025-64155 is under active exploitation, as confirmed by Defused through their honeypot deployments. This critical OS command injection flaw enables unauthenticated remote code execution, posing severe risks to enterprise security monitoring systems. CVE-2025-64155 stems from improper neutralization …

BreachLock Expands Adversarial Exposure Validation (AEV) to Web Applications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, United States, January 15th, 2026, CyberNewsWire BreachLock, a global leader in offensive security, today announced that its Adversarial Exposure Validation (AEV) solution now supports autonomous red teaming at the application layer, expanding beyond its initial network-layer capabilities introduced …

AppGuard Critiques AI Hyped Defenses; Expands its Insider Release for its Next-Generation Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

McLean, Virginia, United States, January 15th, 2026, CyberNewsWire A new Top 10 Cybersecurity Innovators profile by AppGuard has been released, spotlighting growing concerns over AI-enhanced malware. AI makes malware even more difficult to detect. Worse, they use AI to assess, …

Cloudflare Acquires Human Native to Strengthen AI Data Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare, the San Francisco-based cybersecurity and internet infrastructure giant, has acquired Human Native, a UK-based AI data marketplace. The deal aims to empower content creators with control over their data in the generative AI era, addressing rising tensions around web …