Zero-Auth Flaw Exposes DoD Contractor to Cross-Tenant Data Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 A severe zero-authorization vulnerability in Schemata’s API, an AI-powered virtual training platform holding active Department of Defense (DoD) contracts, recently exposed highly sensitive military training materials and …

Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 Cloud identity security relies heavily on Microsoft Entra ID (formerly Azure AD) Conditional Access. It acts as the primary digital gatekeeper, checking user locations, calculating risk scores, …

Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 6, 2026 Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw …

Low Noise, High Confidence: Optimizing SOC Costs with Better Threat Intelligence 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 Reduce SOC Costs with Actionable Threat Intelligence Robust defense systems are built on a clear understanding of current threats and the ability to translate it into consistent decisions and measurable outcomes at optimal cost.  High-performing SOCs achieve this by eliminating unnecessary …

GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications. The update is highly recommended for all …

Cisco to Acquire Astrix Security to Strengthen AI Agent and Non-Human Identity Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has announced its intent to acquire Astrix Security Ltd., an industry leader in Non-Human Identity (NHI) security. This strategic acquisition aims to protect enterprise environments from the expanding attack …

LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cambridge, MA, May 5th, 2026, CyberNewswire New right-sized offering brings advanced encryption, easy API integration, and HITRUST-certified compliance to the most underserved segment in healthcare email — with pricing starting …

Cerberus Stalkerware on Google Play Leverages Accessibility Abuse and Firebase for Remote Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 A dangerous piece of Android stalkerware called Cerberus Anti-theft has been hiding in plain sight on the Google Play Store since October 4, 2023. Sold under the …

Attackers Abuse Amazon SES to Send Authenticated Phishing Emails That Bypass Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 5, 2026 Threat actors are increasingly turning to Amazon’s own cloud email infrastructure to deliver phishing messages that look completely genuine, passing every standard security check along the way. …