Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js issued critical security updates across its active release lines on January 13, 2026, patching vulnerabilities that could lead to memory leaks, denial-of-service attacks, and permission bypasses. These releases address three high-severity flaws, among others, urging immediate upgrades for affected …

FortiOS and FortiSwitchManager Vulnerability Allows Remote Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has disclosed a critical heap-based buffer overflow vulnerability (CWE-122) in the cw_acd daemon of FortiOS and FortiSwitchManager. This flaw enables a remote, unauthenticated attacker to execute arbitrary code or commands by sending specially crafted requests over the network. Organizations …

8000+ SmarterMail Hosts Vulnerable to RCE Attack – PoC Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 8,000 internet-exposed SmarterMail servers remain vulnerable to a critical remote code execution flaw tracked as CVE-2025-52691, according to scans conducted on January 12, 2026. Security researchers identified 8,001 unique IP addresses likely affected out of 18,783 exposed instances, with …

Anthropic Unveils “Claude for Healthcare” to Help Users Understand Medical Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has launched Claude for Healthcare, a new set of tools designed to help doctors, insurance companies, and patients use artificial intelligence for medical purposes while meeting strict privacy regulations. The announcement represents a significant expansion of Claude’s capabilities in …

Threat Actors Leveraging RMM Tools to Attack Users via Weaponized PDF Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of cyberattacks has surfaced where threat actors are using weaponized PDF files to trick users into installing remote monitoring and management tools on their systems. These attacks exploit the trusted nature of RMM software like Syncro, SuperOps, …

Hackers Hijacked Apex Legends Game to Control the Inputs of Another Player Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security incident has emerged in Apex Legends, where attackers gained the ability to remotely control player inputs during active gameplay. The incident came to light when Respawn Entertainment disclosed the vulnerability through their official social media channels on …

Top 10 Best Practices for Cybersecurity Professionals to Secure Your Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s digital world, databases act as fortified storehouses for an organization’s crown jewels its critical data. Yet these vaults face nonstop assaults from cyber threats. As a cybersecurity defender, you stand as the ever-watchful guardian, shielding these assets from …

Hexaware Partners with AccuKnox for Cloud Security Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Menlo Park, USA, January 13th, 2026, CyberNewsWire AccuKnox has entered into a partnership with Hexaware Technologies to expand its Zero Trust cloud security platform into enterprise accounts managing hybrid and multi-cloud infrastructure. With rising complexity across hybrid, multi-cloud, and agentic-AI environments, …

New VoidLink Cloud-Native Malware Attacking Linux Systems with Self-deletion Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cloud-focused malware framework called VoidLink has emerged targeting Linux systems with advanced evasion techniques and self-deletion capabilities. Written in the Zig programming language, this malware represents a major shift in how threat actors approach cloud infrastructure attacks. VoidLink …

Critical ServiceNow Vulnerability Enables Privilege Escalation Via Unauthenticated User Impersonation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security threat to ServiceNow AI Platform deployments, allowing unauthenticated attackers to impersonate legitimate users and execute unauthorized operations. The vulnerability, CVE-2025-12420, was discovered by AppOmni, a SaaS security firm, and disclosed to ServiceNow in October 2025, prompting immediate …