New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has identified a critical bug affecting Android devices where the volume buttons malfunction when the Select to Speak accessibility feature is enabled. The issue causes volume keys to adjust accessibility volume rather than media volume. It prevents photo capture …

Spring CLI Tool Vulnerability Enables Command Execution on the Users Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A command injection vulnerability in the Spring CLI VSCode extension poses a security risk to developers still using the outdated tool. The flaw, tracked as CVE-2026-22718, enables attackers to execute arbitrary commands on affected machines, resulting in a medium-severity impact. …

Top 12 Best Open Source Intelligence Tools (OSINT Tools) for Penetration Testing 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

We all know very well that getting or gathering any information by using various tools becomes really easy. In this article, we have discussed various OSINT tools, as if we search over the internet, then there will be many different …

Top 11 Best DNS Filtering Solutions – 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Before diving into DNS filtering solutions, it’s essential to understand the concept of DNS filtering and its significance in cybersecurity. In today’s digital landscape, cybersecurity has become a critical priority as cyberattacks are increasingly prevalent worldwide. Organizations must protect not …

Microsoft Desktop Window Manager 0-Day Vulnerability Exploited in the wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft patched a critical zero-day information disclosure flaw in its Desktop Window Manager (DWM) on January 13, 2026, in the Patch Tuesday update after detecting active exploitation in the wild. Tracked as CVE-2026-20805, the vulnerability allows low-privilege local attackers to …

Microsoft Patch Tuesday January 2026 – 114 Vulnerabilities Fixed Including 3 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s January 2026 updates fix 114 vulnerabilities, with several remote code execution bugs rated critical across Office applications and Windows services such as LSASS. This Patch Tuesday addresses critical remote code execution flaws and numerous elevation of privilege issues that …

FortiSandbox SSRF Vulnerability Allow Attacker to proxy Internal Traffic via Crafted HTTP Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet disclosed a Server-Side Request Forgery (SSRF) vulnerability in its FortiSandbox appliance on January 13, 2026, urging users to update amid risks of internal network proxied requests. Tracked as CVE-2025-67685 (FG-IR-25-783), the flaw resides in the GUI component and stems …

Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js issued critical security updates across its active release lines on January 13, 2026, patching vulnerabilities that could lead to memory leaks, denial-of-service attacks, and permission bypasses. These releases address three high-severity flaws, among others, urging immediate upgrades for affected …

FortiOS and FortiSwitchManager Vulnerability Allows Remote Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has disclosed a critical heap-based buffer overflow vulnerability (CWE-122) in the cw_acd daemon of FortiOS and FortiSwitchManager. This flaw enables a remote, unauthenticated attacker to execute arbitrary code or commands by sending specially crafted requests over the network. Organizations …

8000+ SmarterMail Hosts Vulnerable to RCE Attack – PoC Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 8,000 internet-exposed SmarterMail servers remain vulnerable to a critical remote code execution flaw tracked as CVE-2025-52691, according to scans conducted on January 12, 2026. Security researchers identified 8,001 unique IP addresses likely affected out of 18,783 exposed instances, with …