PoC Released for Windows Notepad Vulnerability that Enables Malicious Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a high-severity remote code execution (RCE) vulnerability in the modern Windows Notepad application, tracked as CVE-2026-20841, as part of its February 2026 Patch Tuesday release cycle. The …

Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in BeyondTrust’s remote support software is being actively exploited by hackers to deliver dangerous backdoors on compromised systems. The flaw, tracked as CVE-2026-1731, carries a CVSS score …

Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers Using OAuth Apps in Microsoft Entra ID Hackers are increasingly abusing OAuth applications in Microsoft Entra ID to gain persistent access, blending in as normal “business integrations” while keeping access even …

Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens and Gain Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An ongoing phishing campaign that targets Microsoft 365 users by abusing OAuth tokens to gain long‑term access to corporate data, which focuses on business users in North America and aims …

PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates Security 20+ Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PentAGI Penetration Testing Tool PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released …

Google Issues Emergency Chrome Security Update to Address High-Severity PDFium and V8 Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Issues Emergency Chrome Security Update A significant security update for the Chrome Stable Channel to address multiple vulnerabilities, including high-severity flaws affecting the browser’s core engines. The tech giant …

Splunk Enterprise for Windows Vulnerability Let Attackers Hijack DLLs and Gain SYSTEM Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has disclosed a high-severity vulnerability in Splunk Enterprise for Windows that allows a low-privileged local user to escalate their privileges to SYSTEM level through a DLL search-order hijacking attack. …

Adidas Investigates Alleged Data Breach – 815,000 Records of Customer Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adidas has confirmed it is actively investigating a potential data breach involving one of its independent third-party partners after a threat actor operating under the alias “LAPSUS-GROUP” posted claims on …

OpenClaw’s Top Skill is a Malware that Stole SSH Keys, and Opened Reverse Shells in 1,184 Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw’s Top Skill Malware The most downloaded AI agent skill on OpenClaw’s ClawHub marketplace was functional malware, not a productivity tool. OpenClaw, an open-source AI agent platform, operates a public …

Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of a distinct vulnerability disclosure ecosystem within China has introduced a complex layer to the global threat landscape. Unlike the centralized CVE system used internationally, China maintains two …