Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The React2Shell vulnerability (CVE-2025-55182) continues to face a relentless exploitation campaign, with threat actors launching more than 8.1 million attack sessions since its initial disclosure. According to GreyNoise Observation Grid …

Microsoft Enforces Mandatory MFA for Microsoft 365 Admin Center Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is ramping up security measures for its enterprise customers, mandating multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center. The policy takes full effect on February …

New ChatGPT Flaws Allow Attackers to Exfiltrate Sensitive Data from Gmail, Outlook, and GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in ChatGPT allow attackers to exfiltrate sensitive data from connected services like Gmail, Outlook, and GitHub without user interaction. Dubbed ShadowLeak and ZombieAgent, these flaws exploit the AI’s …

New OAuth-Based Attack Let Hackers Bypass Microsoft Entra Authentication Flows to Steal Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The security landscape faced a significant challenge just before the year’s end with the emergence of ConsentFix, an ingenious OAuth-based attack that exploits legitimate authentication flows to extract authorization codes …

Cisco Snort 3 Detection Engine Vulnerability Leaks Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities have been identified in Cisco’s Snort 3 detection engine, posing significant risks to network security infrastructure across multiple Cisco products. These weaknesses stem from improper handling of …

Cisco ISE Vulnerability Let Remote attacker Access Sensitive Data – Public PoC Available

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has patched a critical flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that lets authenticated administrators snoop on sensitive server files. Dubbed CVE-2026-20029, the …

Hackers Can Leverage Kernel Patch Protection to Hide Process from Task Manager

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new technique discovered in 2026 reveals that attackers can manipulate Windows kernel structures to conceal running processes from detection systems, even while modern security layers like PatchGuard protect the …

GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and unauthorized access in self-managed installations. The updated versions …

Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without …