BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Python-based information stealer known as BlankGrabber has been caught using a deceptive certificate loader trick to hide a multi-stage malware delivery chain. First identified in 2023, this threat has …

Stored XSS Bug in Jira Work Management Could Lead to Full Organization Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular collaboration tool within the Atlassian ecosystem is widely used by organizations to track projects, manage approvals, and manage daily tasks. Recently, security researchers at Snapsec uncovered a critical Stored …

CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated cybercrime group has been quietly compromising cloud environments since late 2025, and its activities are now drawing serious concern across the security community. The group, known as …

Vim Vulnerability Let Attackers Execute Arbitrary Command Via Weaponized Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been discovered in Vim, one of the most widely used text editors among developers. This vulnerability allows attackers to execute arbitrary operating system commands simply by …

Critical Grafana Vulnerabilities Let Attackers Achieve Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Urgent security updates for Grafana version 12.4.2 address two critical vulnerabilities that could allow attackers to achieve full remote code execution (RCE) and execute denial-of-service (DoS) attacks. System administrators utilizing …

Critical n8n Vulnerability Let Attackers Achieve Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in n8n, a widely used open-source workflow automation platform, exposes host servers to Remote Code Execution (RCE) attacks. Tracked as CVE-2026-33660, this critical vulnerability allows authenticated …

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Databricks is currently investigating an alleged security compromise connected to the massive TeamPCP software supply chain attack after being alerted by threat intelligence researchers. According to International Cyber Digest, Databricks …

Critical Fortinet Forticlient EMS Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS), tracked as CVE-2026-21643, is actively being exploited in the wild. Threat actors have been leveraging this flaw in …

India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Starting April 1, 2026, the Indian government will effectively ban Chinese video surveillance giants, including Hikvision, Dahua, and TP-Link, from selling internet-connected CCTV cameras in the country. This decisive market …