Node.js 25.5.0 Released Update Root Certificates and New Command-Line Flags

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js version 25.5.0 was released on January 26, 2026, introducing significant developer-focused enhancements and security updates. The release prioritizes simplified application packaging through a new command-line flag while maintaining cryptographic …

CISA releases Secure Connectivity Principles Checklist for Operational Technology Networks Connectivity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC-UK) have jointly released comprehensive guidance on Secure Connectivity Principles for Operational Technology (OT) environments. …

WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security vulnerability in Western Digital’s WD Discovery desktop application has been disclosed, potentially allowing attackers to execute arbitrary code on Windows systems. The flaw, tracked as CVE-2025-30248, affects …

Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Caminho Loader is a new Loader-as-a-Service threat that blends steganography, fileless execution, and cloud abuse to quietly deliver malware across several regions. First seen in March 2025 and believed to …

Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the PyPI-distributed version of PLY (Python Lex-Yacc) 3.11, allowing arbitrary code execution through unsafe deserialization of untrusted pickle files. The vulnerability, assigned CVE-2025-56005, …

APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as …

Multiple Vulnerabilities in React Server Components Enable DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical security vulnerabilities have recently been disclosed in React Server Components, enabling threat actors to launch Denial-of-Service (DoS) attacks against vulnerable servers. The flaws, tracked as CVE-2026-23864 with a …

China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work …

Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly distributing malicious Remote Monitoring and Management (RMM) tools through fake websites that mimic popular software download pages. These deceptive sites impersonate legitimate utilities like Notepad++ and 7-Zip, …

Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released emergency out-of-band security updates on January 26, 2026, to address CVE-2026-21509, a zero-day security feature bypass vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated …