Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Threat actors are constantly hunting for infrastructure weaknesses, and a newly discovered batch of vulnerabilities in GitLab just handed them a dangerous roadmap. On May 13, 2026, GitLab rolled out emergency security updates to address multiple high-severity …

Lyrie.ai Launches the Global Identity Standard for the AI Agent Age & Anthropic’s Cyber Verification Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 DUBAI, UAE — May 11, 2026 — As the internet transitions from a playground of chatbots to a workforce of autonomous agents, the question isn’t just what AI can do—it’s who the AI is. Today, OTT Cybersecurity LLC officially launched …

OpenAI Hit with Class-Action Privacy Lawsuit for Sharing ChatGPT Data with Google and Meta

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 OpenAI Global LLC is facing a new class‑action complaint in the Southern District of California that accuses the company of quietly wiring its ChatGPT web interface with Meta’s Facebook Pixel and Google Analytics, turning highly sensitive chatbot …

Windows DNS Client Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly disclosed vulnerability in the Microsoft Windows DNS Client could let attackers silently execute malicious code across enterprise networks, exposing a massive attack surface. Officially designated as CVE-2026-41096, this critical security flaw carries a severe CVSS …

Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution …

Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly disclosed critical vulnerability in MongoDB could allow threat actors to execute arbitrary code, potentially handing them complete control over affected servers and exposing millions of records to theft. The vulnerability, officially tracked as CVE-2026-8053, directly …

The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A ransomware group that only surfaced in mid-2025 has already made a significant mark on the threat landscape. The Gentlemen, a ransomware-as-a-service (RaaS) operation, has quickly risen to become one of the most active ransomware programs in …

Windows BitLocker 0-Day Vulnerability Enables Access to Encrypted Drives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Two new unpatched Windows BitLocker zero-day vulnerabilities significantly compromise Microsoft’s ecosystem. The exploits include a critical BitLocker encryption bypass called YellowKey and a privilege escalation flaw named GreenPlasma. The most critical of these flaws, dubbed “YellowKey,” enables …

How Top SOCs and MSSPs Prevent Phishing Incidents Missed by Email Filters 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 13, 2026 Prevent Phishing Incidents Missed by Email Filters Email filters are important, but they can’t remove phishing risk on their own. Today’s campaigns are built to slip through the cracks, using fresh domains, CAPTCHA checks, fake login pages, OTP theft, and …

Foxconn Confirms Cyberattack After Nitrogen Ransomware Gang Claim

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 13, 2026 Foxconn has officially confirmed a cyberattack targeting its North American operations after the Nitrogen ransomware gang publicly listed the company on its data leak site, claiming to have stolen a staggering 8 terabytes of sensitive data. The …