Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kubernetes CSI Driver NFS Vulnerability A path traversal vulnerability has been identified in the Kubernetes Container Storage Interface (CSI) Driver for NFS, potentially allowing attackers to delete or modify unintended directories on NFS servers. The flaw stems from insufficient validation …

New Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues Microsoft has rolled out an out-of-band update for Windows 11 users to address a frustrating interface bug affecting Bluetooth device visibility. Released on March 16, 2026, this emergency patch resolves a …

Angular XSS Vulnerability Exposes Thousands of web Applications to XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Angular XSS Vulnerability Exposes web Applications A high-severity Cross-Site Scripting (XSS) vulnerability has been discovered in the widely used Angular framework. Tracked as CVE-2026-32635 and categorized under CWE-79, this flaw affects both the @angular/compiler and @angular/core packages. Because Angular powers countless enterprise and consumer …

Orchid Security Recognized by Gartner® as a Representative Vendor of Guardian Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, United States, March 17th, 2026, CyberNewswire Unleash AI adoption securely: discover, attribute, and govern AI agents throughout the enterprise Orchid Security, the company bringing clarity and control to the complexity of enterprise identity, today announced it has been …

Phishers Weaponize Safe Links With Multi-Layered URL Rewriting to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attackers have found a way to turn a standard security feature against the very users it was built to protect. By abusing URL rewriting — a defensive mechanism embedded in most enterprise email gateways — threat actors are weaponizing …

New ‘Payload’ Ransomware Uses Babuk-Style Encryption Against Windows and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified ransomware strain called “Payload” has emerged as a serious threat to organizations across multiple sectors, combining strong encryption techniques with advanced anti-forensic capabilities. The group behind it has been active since at least February 17, 2026 — …

CISA Warns of Chrome 0-Day Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns of Chrome 0-Day Vulnerabilities Exploit An urgent warning regarding two highly critical zero-day vulnerabilities affecting Google Chrome and related products. These flaws have been officially added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, indicating that malicious hackers are …

Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information. The threat actors are not …

Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware, first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean …

Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to …