OpenSSL Vulnerabilities Allow Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenSSL patched 12 vulnerabilities on January 27, 2026, including one high-severity flaw that could lead to remote code execution. Most issues cause denial-of-service attacks but highlight risks in parsing untrusted …

Google Warns of WinRAR Vulnerability Exploited to Gain Control Over Windows System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in WinRAR, one of the most widely used file compression tools for Windows, has become a favorite weapon for attackers seeking unauthorized access to computer systems. …

Critical Vulnerability in VM2 Sandbox Library for Node.js Let Attackers run Untrusted Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical sandbox escape vulnerability has been identified in vm2. This widely used Node.js library provides sandbox isolation for executing untrusted code. The flaw, tracked as CVE-2026-22709 (GHSA-99p7-6v5w-7xg8), affects all …

Attackers Hijacking Official GitHub Desktop Repository to Distribute Malware as Official Installer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have discovered a dangerous way to trick developers into downloading malware by exploiting how GitHub works. The attack involves creating fake versions of the GitHub Desktop installer and making …

Instagram, Facebook, and WhatsApp to Test New Premium Subscriptions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta is gearing up to roll out premium subscription tiers across its flagship apps, Instagram, Facebook, and WhatsApp, offering users exclusive features to boost productivity, creativity, and AI-driven interactions. The …

G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On January 23rd, 2026, security researchers discovered a dangerous npm package named ansi-universal-ui that disguised itself as a legitimate user interface component library. The deceptive package description claimed to offer …

Hackers Using Teams to Deliver Malicious Content Posing as Microsoft Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has been identified in which threat actors are abusing legitimate Microsoft Teams functionality to distribute malicious content that appears to originate from trusted Microsoft services. By …

Attackers Exploiting React2Shell Vulnerability to Attack IT Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have started targeting companies in the insurance, e-commerce, and IT sectors through a critical vulnerability tracked as CVE-2025-55182, commonly known as React2Shell. This flaw exists in the Flight …

Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage. That’s a Business Problem 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security Operations Centers live or die by their ability to respond quickly and accurately to alerts. At the heart of this process is alert triage — the initial evaluation that decides whether an alert is a …

Hackers are Leveraging SEO Poisoning to Attack Users Looking for Legitimate Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have adopted a deceptive strategy to compromise users searching for common software applications online. These attackers are using search engine optimization poisoning techniques to place malicious links at the …