FortiSandbox Vulnerability Exposes VNC Server to Unauthenticated Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could let unauthenticated attackers gain access to the VNC server of virtual machines used for malware scanning. Tracked …

AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, …

Miasma Turns Trusted npm Packages Into Persistent Backdoors for Developer Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Miasma has returned through software packages that many developers would normally trust. Four AsyncAPI packages on npm were altered to deliver a Miasma v3 payload, creating a …

xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A wire-level analysis of xAI’s Grok Build CLI revealed that version 0.2.93 transmitted unredacted file contents, including secrets from .env files, and uploaded full Git repositories along …

VMware Avi Load Balancer Vulnerabilities Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Broadcom-owned VMware has disclosed multiple security flaws in its Avi Load Balancer platform (formerly NSX Advanced Load Balancer) that let attackers bypass authentication controls and gain unauthorized …

Pro-Iran Hacktivists Use Telegram-Coordinated DDoS and Hack-and-Leak Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Pro-Iran hacktivist networks are turning Telegram channels into hubs for cyber retaliation. Their campaigns combine website-disrupting DDoS floods with hack-and-leak claims, using public posts to recruit supporters, …

New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT …

CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS …

UK and Allies Warn of Russian Hackers Actively Hacking Organizations’ Routers Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The UK, joined by international cybersecurity partners, has issued an urgent warning about Russian state-backed hackers targeting poorly secured routers and network devices worldwide. The alert focuses …

SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory Corruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 SAP has released its July 2026 Security Patch Day updates, addressing a critical memory corruption vulnerability in the SAP NetWeaver Application Server ABAP. The most severe issue, …