Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting …

Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, …

New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has entered a dangerous new chapter with the discovery of VoidLink, the first documented advanced malware framework built almost entirely by artificial intelligence. Unlike earlier attempts where …

Microsoft Investigating Issue Impacting Exchange Online, Teams, and M365 Suite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed it is actively investigating a new service incident affecting multiple core services within the Microsoft 365 ecosystem. The company acknowledged the disruption on Wednesday evening, following reports …

New Magecart Attack Inject Malicious JavaScript to Skim Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Magecart-style campaign has emerged, targeting online shoppers through malicious JavaScript code designed to steal payment information directly from ecommerce websites. The attack works by injecting hidden scripts into …

Alleged Ransomware Attack on Apple’s Second-Largest Manufacturer Luxshare – Confidential Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A ransomware attack has reportedly exposed confidential internal documents at a major electronics manufacturer. The breach compromises the company’s critical role in Apple’s global supply chain, including AirPods manufacturing, iPhone …

ErrTraffic Fueling ClickFix by Breaking the Page Visually and Turns Attack to GlitchFix

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new social engineering technique called GlitchFix has emerged, powered by ErrTraffic—a specialized traffic distribution system designed to trick website visitors into downloading malware through visually broken web pages. The …

Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE). The patches resolve issues ranging from high-severity authentication flaws …

LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert regarding an active phishing campaign that commenced on January 19, 2026. The malicious actors are impersonating LastPass support staff and sending fraudulent emails claiming urgent vault …

AI Phishing Is Your Company’s Biggest Security Risk in 2026: Here’s How to Stop It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing used to be easy to spot. Bad grammar, strange links, obvious scams. That version is gone.  In 2026, phishing is polished, well-written, and often smarter than it has any right …