TP-Link Vulnerability Allows Authentication Bypass Via Password Recovery Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication vulnerability affecting TP-Link’s VIGI surveillance camera lineup has been disclosed, enabling attackers on local networks to reset administrative credentials without authorization. Tracked as CVE-2026-0629, the flaw resides in the camera’s web interface password recovery function and carries …

Open Source Firewall OPNsense 25.7.11 Released With Host Discovery Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular open-source firewall and routing platform built on FreeBSD, released version 25.7.11 on January 15, 2026, bringing significant improvements, including a new host discovery service designed to enhance network management capabilities. The release marks an essential incremental update that …

Raaga Data Breach Exposes 10.2 Million User Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Indian music streaming platform Raaga suffered a significant data breach in December 2025, compromising the personal information of 10.2 million users. The stolen database was subsequently offered for sale on a prominent underground hacking forum, raising serious concerns about user …

VoidLink Rewrites Rootkit Playbook with Server-Side Kernel Compilation and AI-Assisted Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VoidLink emerges as a significant threat to Linux cloud environments, representing a major shift in how rootkits are designed and deployed. This Chinese-developed malware framework was first discovered by Check Point Research on January 13, 2026, marking the beginning of …

Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new clipboard hijacker is quietly draining cryptocurrency from gamers and streamers by abusing trust inside Discord communities. The campaign centers on a malicious Windows program shared as a supposed streaming or security tool. Once installed, it silently watches the …

Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than destructive activity. The malware operates silently in the background, collecting …

Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Seven vulnerabilities were disclosed in Process Optimization (formerly ROMeo) 2024.1 and earlier on January 13, 2026, including a critical flaw enabling unauthenticated SYSTEM-level remote code execution. The most severe vulnerability enables unauthenticated attackers to achieve remote code execution under system …

WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Google’s Fast Pair protocol that allows attackers to hijack Bluetooth audio accessories and track users without their knowledge or consent.​ Security researchers from KU Leuven have uncovered a vulnerability, tracked as CVE-2025-36911 and dubbed WhisperPair, that …

Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. The malware targets users …

Pulsar RAT Using Memory-Only Execution & HVNC to Gain Invisible Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pulsar RAT has emerged as a sophisticated derivative of the open-source Quasar RAT, introducing dangerous enhancements that enable attackers to maintain invisible remote access through advanced evasion techniques. This modular Windows-focused remote administration tool represents a significant evolution in threat …