Hackers Actively Scanning Citrix NetScaler Infrastructure to Discover Login Panels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected between January 28 and February 2, 2026, by the GreyNoise Global Observation Grid. The coordinated operation …

Ingress-Nginx Vulnerability Allow Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ingress-Nginx Vulnerability A critical security vulnerability has been discovered in ingress-nginx, a popular Kubernetes ingress controller, that could allow authenticated attackers to execute arbitrary code and access sensitive cluster secrets. …

CISA Warns of SolarWinds Web Help Desk RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns SolarWinds Web Help Desk Vulnerability An urgent warning regarding a critical remote code execution (RCE) vulnerability in SolarWinds Web Help Desk. The vulnerability, tracked as CVE-2025-40551, exploits unsafe …

Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Vulnerabilities Arbitrary Code Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and …

Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

React Server Vulnerability Exploited Two months following the disclosure of CVE-2025-55182, exploitation activity targeting React Server Components has evolved from broad scanning into consolidated, high-volume attack campaigns. According to telemetry …

GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GlassWorm has emerged as a serious threat to developers using the Open VSX Registry, where popular VSX extensions were silently turned into delivery vehicles for malware. Threat actors compromised a …

Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat …

Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are launching a dangerous phishing campaign that tricks users into giving away their login credentials by impersonating Dropbox. This attack uses a multi-stage approach to bypass email security checks …

Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical remote code execution vulnerability in React Native’s Metro Development Server to deliver advanced malware payloads across Windows and Linux systems. VulnCheck’s Canary honeypot …

Foxit PDF Editor Vulnerabilities Let Attackers Execute Arbitrary JavaScript

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security updates addressing critical cross-site scripting (XSS) vulnerabilities in Foxit PDF Editor Cloud that could allow attackers to execute arbitrary JavaScript code in users’ browsers. The vulnerabilities were discovered in …