Aembit Announces Agenda and Speaker Lineup for NHIcon 2026 on Agentic AI Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Silver Spring, Maryland, January 15th, 2026, CyberNewsWire Aembit today announced the agenda and speaker lineup for NHIcon 2026: The Rise of Agentic AI Security, a virtual conference scheduled for Jan. 27. The second-annual event will examine the technical, operational, and …

Windows Remote Assistance Vulnerability Allow Attacker to Bypass Security Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security updates addressing CVE-2026-20824, a protection mechanism failure in Windows Remote Assistance that permits attackers to circumvent the Mark of the Web (MOTW) defense system. The vulnerability was disclosed on January 13, 2026, and affects multiple Windows platforms spanning …

MonetaStealer Malware Powered with AI Code Attacking macOS Users in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new information-stealing malware named MonetaStealer has been discovered actively targeting macOS users through deceptive file disguises and social engineering tactics. Security researchers at Iru first identified this threat on January 6, 2026, when they found a suspicious Mach-O binary …

New Sicarii RaaS Operation Attacks Exposed RDP Services and Attempts to Exploit Fortinet Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, a previously unknown ransomware-as-a-service operation named Sicarii emerged across underground platforms, introducing itself as an Israeli or Jewish affiliated group. The operation stands apart from typical financially motivated ransomware due to its explicit use of Hebrew language, …

Turla’s Kazuar v3 Loader Leverages Event Tracing for Windows and Bypasses Antimalware Scan Interface

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Turla, a sophisticated threat actor known for targeted cyber attacks, has deployed an upgraded version of its Kazuar v3 loader that introduces advanced evasion techniques designed to bypass modern security defenses. This latest iteration, discovered in January 2026, showcases a …

Microsoft and Authorities Dismatles BEC Attack Chain Powered by RedVDS Fraud Engine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint operation led by Microsoft and international law enforcement has dismantled a business email compromise (BEC) attack chain powered by the RedVDS fraud engine. RedVDS operated as a low‑cost “cybercrime subscription” platform, giving criminals disposable virtual machines that looked …

Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack any User Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in Cal.com’s scheduling platform enables attackers to hijack any user account by exploiting a flaw in the NextAuth JWT callback mechanism. Tracked as CVE-2026-23478, this vulnerability affects versions from 3.1.6 up to but not including …

HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett Packard Enterprise (HPE) has disclosed four high-severity vulnerabilities in its Aruba Networking Instant On devices that could allow attackers to access sensitive network information and disrupt operations. The security flaws, identified as CVE-2025-37165, CVE-2025-37166, CVE-2023-52340, and CVE-2022-48839, affect devices …

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights a serious issue in how malicious infrastructure can hide within …

Palo Alto Networks Firewall Vulnerability Allows Unauthenticated Attackers to Trigger Denial of Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has patched a critical denial-of-service vulnerability in its PAN-OS firewall software, tracked as CVE-2026-0227, which lets unauthenticated attackers disrupt GlobalProtect gateways and portals. The flaw carries a CVSS v4.0 base score of 7.7 (HIGH severity), stemming from …