HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett Packard Enterprise (HPE) has disclosed four high-severity vulnerabilities in its Aruba Networking Instant On devices that could allow attackers to access sensitive network information and disrupt operations. The security …

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights …

Palo Alto Networks Firewall Vulnerability Allows Unauthenticated Attackers to Trigger Denial of Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has patched a critical denial-of-service vulnerability in its PAN-OS firewall software, tracked as CVE-2026-0227, which lets unauthenticated attackers disrupt GlobalProtect gateways and portals. The flaw carries a …

Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system …

Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware loader known as CastleLoader has emerged as a critical threat to US government agencies and critical infrastructure organizations. First identified in early 2025, this stealthy malware has …

Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, …

New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel single-click attack targeting Microsoft Copilot Personal that enables attackers to silently exfiltrate sensitive user data. The vulnerability, now patched, allowed threat actors to hijack sessions via a phishing …

North Korean Hackers use Code Abuse Tactics for ‘Contagious Interview’ Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors have launched a sophisticated social engineering campaign targeting software developers through fake recruitment offers. The campaign, known as Contagious Interview, uses malicious repositories disguised as technical …

SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Austin, TX / USA, January 14th, 2026, CyberNewsWire New monitoring capability delivers unprecedented visibility into vendor identity exposures, moving enterprises and government agencies from static risk scoring to protecting against …

LLMs are Accelerating the Ransomware Lifecycle to Gain Speed, Volume, and Multilingual Reach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large language models are changing how ransomware crews plan and run their attacks. Instead of inventing new kinds of malware, LLMs are speeding up every step of the existing ransomware …