Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical path traversal vulnerability in AdonisJS has been discovered that could allow remote attackers to write arbitrary files to server filesystems, potentially leading to complete system compromise. The vulnerability, tracked as CVE-2026-21440, affects the bodyparser module of the popular TypeScript-first …

Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued its January 2026 Android Security Bulletin, urging users to update to the 2026-01-05 patch level or later to mitigate a critical vulnerability in Dolby components. The standout issue, CVE-2025-54957, targets the Dolby Digital Plus (DD+) codec and …

NordVPN Denies Data Breach Following Threat Actor Claim on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NordVPN has firmly rejected claims of a data breach after a threat actor surfaced alleged stolen data on a dark web breach forum, purporting to expose the VPN provider’s Salesforce development server. The incident, first spotted on January 4, underscores …

New Tool to Remove Copilot, Recall and Other AI Tools From Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s aggressive push to integrate artificial intelligence features into Windows 11 has prompted developers to create the RemoveWindowsAI project. An open-source tool designed to remove or disable unwanted AI components from the operating system. RemoveWindowsAI is a community-driven utility available …

Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The holiday season has brought with it a surge in sophisticated phishing attacks that combine two dangerous tactics: credential harvesting through spoofed Docusign notifications and identity theft through fake loan application forms. These coordinated campaigns exploit the seasonal chaos of …

CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign has emerged across Central and Eastern Europe, causing widespread concern among cybersecurity professionals and organizations. CloudEyE, a Malware-as-a-Service downloader and cryptor, has rapidly gained traction among threat actors seeking to distribute other harmful malware payloads. In …

New Critical n8n Vulnerability Allow Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in n8n, the popular open-source workflow automation platform, enabling authenticated attackers to execute arbitrary commands on host systems. The vulnerability, tracked as CVE-2025-68668, has been assigned a severe CVSS score of 9.9 out of …

Connex IT Partners with AccuKnox for Zero Trust CNAPP Security in Southeast Asia

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Menlo Park, India, January 6th, 2026, CyberNewsWire AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), has appointed Connex Information Technologies as its authorised distribution partner across South and Southeast Asia. The partnership aligns AccuKnox with Connex, …

Cursor, Windsurf & Google Antigravity IDEs Recommend Malicious App Extension to Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in popular AI-powered development environments has put millions of developers at risk of installing malicious software extensions. The Cursor, Windsurf, and Google Antigravity AI IDEs, with over a million users combined, were found recommending extensions that …

New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed …