CISA Warns of Fortinet FortiWeb OS Command Injection Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical vulnerability affecting Fortinet FortiWeb appliances that threat actors are currently exploiting in active attacks. The …

Microsoft Teams New Feature Let Users Report Messages Incorrectly Flagged as Security Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is introducing a new capability in Teams that allows users to report messages they believe were mistakenly flagged as security threats. The feature represents a significant step toward improving …

Multiple Vulnerabilities in D-Link EoL/EoS Routers Allows Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities affect D-Link DIR-878 routers across all models and firmware revisions. These devices reached the end of life on January 31, 2021. They will no longer receive security …

New npm Malware Campaign Verifies if the Visitor is a Victim or a Researcher Before Triggering Infection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign targeting the npm ecosystem has emerged, deploying a clever detection system that distinguishes between regular users and security researchers. The threat actor, operating under the alias …

New .NET Malware Hides Lokibot Malware within PNG/BMP Files to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity threats continue to evolve with sophisticated evasion methods. A new .NET-based malware loader has emerged that demonstrates an advanced approach to concealing the notorious Lokibot trojan within image files. …

New Sneaky 2FA Phishing Kit with BitB Technique Attacking Users to Steal Microsoft Account Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Sneaky2FA phishing service has recently added a dangerous new capability to its toolkit that makes stealing Microsoft account credentials even easier for attackers. Push Security analysts and researchers have …

Microsoft Integrated Azure Firewall With AI-powered Security Copilot

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has enhanced its cloud security capabilities by integrating Azure Firewall with Security Copilot, an AI-powered security solution designed to help security teams work faster and more efficiently. This integration …

Critical SolarWinds Serv-U Vulnerabilities Let Attackers Execute Malicious Code Remotely as Admin

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released security patches addressing three critical remote code execution vulnerabilities in Serv-U that could allow attackers with administrative privileges to execute arbitrary code on affected systems. The vulnerabilities …

Microsoft Threat Intelligence Briefing Agent Now Integrated With the Defender Portal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft unveiled significant enhancements to threat intelligence at Ignite 2025, bringing the Threat Intelligence Briefing Agent directly into the Defender portal. This integration marks a pivotal shift in how security …

Malicious ‘Free’ VPN Extension with 9 Million Installs Hijacks User Traffic and Steals Browsing Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deceptive browser campaign has exposed millions of users to extensive surveillance through seemingly innocent VPN extensions. Chrome extensions marketed as “Free Unlimited VPN” services accumulated over 9 million installations …