Microsoft Unveils New Teams Optimizations for Windows App on iOS & Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft New Teams Optimizations Windows App on iOS & Android Microsoft has officially announced the general availability of new Microsoft Teams optimizations for the Windows App on both iOS and Android platforms. Released on March 18, 2026, this update introduces …

CISA Warns of Cisco Secure Firewall Management Center 0-Day Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Cisco Secure Firewall Management Center 0-Day Exploit An urgent warning highlights a critical zero-day in Cisco products, now added to the CISA Known Exploited Vulnerabilities Catalog after active exploitation in ransomware campaigns. Network defenders and security administrators are …

Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attackers have widened their approach to defeating endpoint security, moving well past the technique of exploiting vulnerable drivers. For years, the Bring Your Own Vulnerable Driver (BYOVD) method was the primary way attackers disabled security tools before launching their …

Critical Jenkins Vulnerabilities Expose CI/CD Servers to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins Vulnerabilities Expose CI/CD Servers A critical security advisory addressing multiple high-severity vulnerabilities in Jenkins core and the LoadNinja plugin. Issued on March 18, 2026, the alert warns that these flaws could allow attackers to execute arbitrary code and fully …

Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Navia Data Breach A prominent U.S. consumer-focused benefits administrator has disclosed a significant data breach exposing the sensitive personal and health information of approximately 2.7 million individuals.​ On January 23, 2026, Navia detected suspicious activity within its network environment. Following …

Bamboo Data Center and Server Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bamboo Data Center and Server Vulnerability A high-severity security flaw has been addressed in Bamboo Data Center, an enterprise platform widely used for software build and release management. Tracked as CVE-2026-21570, this Remote Code Execution (RCE) vulnerability allows authenticated threat …

New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered infostealer malware named Speagle has emerged as a serious threat targeting organizations that run Cobra DocGuard, a document security and encryption platform developed by Chinese company EsafeNet. The malware is engineered to blend into its host environment, …

Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apex AI Penetration Testing Agent Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, hints, or predefined attack paths. This enables it to discover, …

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on …

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive email data. Dubbed “Operation GhostMail,” the campaign stands out for …