Microsoft SharePoint Server 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day spoofing vulnerability in Microsoft SharePoint Server is being actively exploited in the wild, Microsoft confirmed on April 14, 2026, as part of its monthly security update cycle. …

Security Risk Advisors Purple Team Participants Can Now Earn CPE Credits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Philadelphia, United States / Pennsylvania, April 14th, 2026, CyberNewswire GIAC and ISC2 now recognize active participation in SRA Purple Team exercises as an eligible Continuing Professional Education (CPE) activity. Teams can earn CPE credits while …

Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet released a sweeping batch of security advisories on April 14, 2026, addressing 11 vulnerabilities spanning multiple product lines, including two rated Critical, two rated High, and seven rated Medium …

Critical etcd Auth Bypass Flaw Allows Unauthorized Access to Sensitive Cluster APIs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability has emerged in etcd, the foundational distributed key-value store that supports countless cloud-native systems and Kubernetes clusters globally. Tracked as CVE-2026-33413, this high-severity flaw carries …

Ivanti Neurons for ITSM Vulnerabilities Allow Remote Attacker to Obtain User Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has released security updates addressing two medium-severity vulnerabilities in Ivanti Neurons for ITSM (N-ITSM), its on-premise IT service management platform. The flaws, if exploited, could allow remote authenticated attackers …

CISA Warns of Microsoft Exchange and Windows CLFS Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to organizations regarding two severe Microsoft vulnerabilities. On April 13, 2026, the agency officially added flaws affecting Microsoft …

New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Android malware called Mirax has been quietly circulating in underground criminal forums since late 2025, posing a growing threat to mobile users across Europe and beyond. What …

Hackers Leave Credential Stuffing Botnet Wide Open With Full Worker Access and Root Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A live credential stuffing botnet targeting Twitter/X accounts has been found completely exposed to the internet, with no password required to access its control panel, worker server credentials, or real-time …