F5 NGINX Plus and Open Source Vulnerability Allow Attackers to Execute Code Using MP4 file

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been disclosed affecting both NGINX Open Source and NGINX Plus. Tracked formally as CVE-2026-32647, this security flaw carries a CVSS v4.0 base score of 8.5 and …

Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla released Firefox 149 on March 24, 2026, delivering one of the largest security advisories in the browser’s recent history, addressing 37 vulnerabilities spanning memory corruption, sandbox escapes, use-after-free flaws, …

OpenAI to Shut Down Sora Video Platform, Pivots to Enterprise and Developer Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI is pulling the plug on its Sora video generation platform, a high-profile product launched to widespread attention last year that has since quietly faded from the spotlight. The shutdown …

Hackers Exploiting Magento to Execute Remote Code and Gain Complete Account Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unrestricted file upload vulnerability, dubbed “PolyShell,” is actively being exploited in Magento and Adobe Commerce stores. Discovered by the Sansec Forensics Team, this flaw allows unauthenticated attackers to …

Multiple TP-Link Vulnerabilities Allow Attackers to Execute Arbitrary Commands on System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link has recently issued a critical security advisory addressing multiple high-severity vulnerabilities impacting its Archer NX series routers. These flaws, which affect the Archer NX200, NX210, NX500, and NX600 models, …

Russian Initial Access Broker Sentenced to Prison for Enabling Ransomware Attacks on U.S. Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Aleksei Volkov, a 26-year-old Russian national, has been sentenced to 81 months in federal prison for operating as an Initial Access Broker (IAB). His illicit activities directly enabled major cybercrime …

ClawHub Vulnerability Let Attackers Manipulate Rankings to Become the #1 Skill

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security research team has uncovered a critical vulnerability in ClawHub, the public skills registry for the OpenClaw agentic ecosystem. This flaw allowed attackers to artificially inflate the download counts of …

Google Authenticator’s Hidden Passkey Architecture Could Open New Passwordless Attack Paths

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Passwordless authentication was supposed to mark the end of account takeovers. Designed to replace traditional passwords with cryptographic keys tied to physical devices, it promised a future where stolen credentials …

FCC Blocks Foreign-made Consumer Routers Over Security Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Communications Commission (FCC) announced a major update to its Covered List, officially prohibiting the approval of new consumer-grade network routers produced in foreign countries. This regulatory action prevents …

LiteLLM Python Package With 95 Million Downloads Compromised by TeamPCP Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely used open-source Python library was compromised on the Python Package Index (PyPI). Versions 1.82.7 and 1.82.8 of the package, which route requests across various LLM providers and have …