ChatGPT Health – A Dedicated Space for Health Queries With Strong Privacy and Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has launched ChatGPT Health, a specialized platform that helps users securely manage their health information and receive intelligent support for wellness-related questions. With over 230 million people using ChatGPT weekly for health inquiries, the company recognized the need for a …

Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The React2Shell vulnerability (CVE-2025-55182) continues to face a relentless exploitation campaign, with threat actors launching more than 8.1 million attack sessions since its initial disclosure. According to GreyNoise Observation Grid data, daily attack volumes have stabilized at 300,000–400,000 sessions since …

Microsoft Enforces Mandatory MFA for Microsoft 365 Admin Center Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is ramping up security measures for its enterprise customers, mandating multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center. The policy takes full effect on February 9, 2026, building on a softer rollout that began in …

New ChatGPT Flaws Allow Attackers to Exfiltrate Sensitive Data from Gmail, Outlook, and GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in ChatGPT allow attackers to exfiltrate sensitive data from connected services like Gmail, Outlook, and GitHub without user interaction. Dubbed ShadowLeak and ZombieAgent, these flaws exploit the AI’s Connectors and Memory features for zero-click attacks, persistence, and even …

Trump Signals U.S. Cyber Role in Caracas Blackout During Maduro Capture

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Caracas went dark just as U.S. forces moved to seize Venezuelan leader Nicolás Maduro on Saturday. The blackout did more than hide troops; it showed how malware can shape modern battles. U.S. Cyber Command and allied units are believed to …

New OAuth-Based Attack Let Hackers Bypass Microsoft Entra Authentication Flows to Steal Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The security landscape faced a significant challenge just before the year’s end with the emergence of ConsentFix, an ingenious OAuth-based attack that exploits legitimate authentication flows to extract authorization codes from Microsoft Entra systems. This attack represents an evolution of …

Cisco Snort 3 Detection Engine Vulnerability Leaks Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities have been identified in Cisco’s Snort 3 detection engine, posing significant risks to network security infrastructure across multiple Cisco products. These weaknesses stem from improper handling of Distributed Computing Environment and Remote Procedure Call (DCE/RPC) requests, allowing …

Cisco ISE Vulnerability Let Remote attacker Access Sensitive Data – Public PoC Available

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has patched a critical flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that lets authenticated administrators snoop on sensitive server files. Dubbed CVE-2026-20029, the vulnerability stems from a flaw in XML parsing in the …

Hackers Can Leverage Kernel Patch Protection to Hide Process from Task Manager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique discovered in 2026 reveals that attackers can manipulate Windows kernel structures to conceal running processes from detection systems, even while modern security layers like PatchGuard protect the system. Outflank analysts identified a method that exploits the timing …

GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and unauthorized access in self-managed installations. The updated versions 18.7.1, 18.6.3, and 18.5.5 were deployed to GitLab.com on January …