Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious …

New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and Accessibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote actions and deceptive login windows, turning …

Hackers Turn Trusted Node.js Runtime Into Malware Launcher in Ransomware-Linked Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses, according to new findings from the Symantec Threat Hunter Team. Since February 2026, …

Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked …

Microsoft Teams, Outlook Crashes Following August 2026 Updates on ARM-Based Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a known issue causing Microsoft Teams and the new Outlook for Windows to crash or fail to launch on ARM-based PCs after installing security updates released on …

The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than …

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 …

Malicious Apache Modules Turn Trusted Government Websites Into Stealth Phishing Proxies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious scam sites, attackers are using compromised web servers …

VPN Is the Biggest Backdoor Into Your Plant — Here’s What Should Replace It on Your OT Network   

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every industrial organisation now lets someone in from the outside — OEM vendors, system integrators, remote engineers. How they get in determines whether a plant’s biggest convenience becomes its biggest breach path.  Remote Access Has Become OT’s Biggest …

Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Tracked as CVE-2026-20212, the …