Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited in the wild, allowing unauthenticated remote attackers to fully bypass authentication and seize administrative control of enterprise network infrastructure. Tracked as CVE-2026-20182 with a …

Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Russian state-sponsored hacking group known as Sandworm has been caught making a calculated pivot from compromised IT networks into operational technology systems that control physical infrastructure. The campaign is alarming because it does not rely on …

Chinese APT Hackers Exploit Microsoft Exchange to Breach Energy Sector Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Chinese state-linked hacking group known as FamousSparrow has quietly infiltrated an Azerbaijani oil and gas company, exploiting an unpatched Microsoft Exchange server to plant multiple backdoors inside the network. The attack ran from late December 2025 …

New Malware Framework Enables Screen Control, Browser Artifact Access, and UAC Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly uncovered malware framework is raising serious alarms across the cybersecurity community. Researchers have identified a previously unknown implant called TencShell, a sophisticated tool capable of giving attackers full remote control over a compromised system. The …

Anthropic’s Mythos AI Reportedly Found macOS Vulnerabilities that Could Bypass Apple Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Security researchers at Calif, a Palo Alto-based cybersecurity firm, have used techniques derived from an early version of Anthropic’s secretive Mythos AI model to uncover two previously undocumented vulnerabilities in Apple’s macOS. The bugs were chained together …

Hackers Compromise 170 npm Packages to Steal GitHub, npm, AWS, and Kubernetes Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A sprawling supply chain attack has put software developers worldwide on high alert after hackers compromised more than 170 npm packages and two PyPI packages in a coordinated credential theft campaign. The infected packages are collectively downloaded …

Amazon Quick Bug Exposed AI Chat Agents to Users Blocked by Custom Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Imagine locking your organization’s sensitive data behind a heavy vault door, only to realize the locking mechanism is entirely missing. Security researchers at Fog Security recently uncovered a severe authorization bypass in Amazon Quick’s AI Chat Agents. …

New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical vulnerability in the widely used Exim mail server allows unauthenticated attackers to execute arbitrary code and fully compromise exposed servers. Federico Kirschbaum, head of the Security Lab at XBOW, discovered and reported the issue, which …

Dell Support assist Updates Forces Windows Systems to BSOD Loop

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A faulty update to Dell’s SupportAssist Remediation service is sending thousands of Dell and Alienware laptop users into endless Blue Screen of Death (BSOD) loops, with systems crashing every 30 minutes and displaying the dreaded CRITICAL_PROCESS_DIED stop …

Microsoft Research Shows AI Can Generate Realistic Command Lines and Process Telemetry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Artificial intelligence is now capable of generating attack telemetry that looks and behaves like the real thing, and that is changing how security teams think about testing their defenses. In new work, Microsoft researchers show that large …