New Critical n8n Vulnerability Allow Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in n8n, the popular open-source workflow automation platform, enabling authenticated attackers to execute arbitrary commands on host systems. The vulnerability, tracked as CVE-2025-68668, has been assigned a severe CVSS score of 9.9 out of …

Connex IT Partners with AccuKnox for Zero Trust CNAPP Security in Southeast Asia

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Menlo Park, India, January 6th, 2026, CyberNewsWire AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), has appointed Connex Information Technologies as its authorised distribution partner across South and Southeast Asia. The partnership aligns AccuKnox with Connex, …

Cursor, Windsurf & Google Antigravity IDEs Recommend Malicious App Extension to Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in popular AI-powered development environments has put millions of developers at risk of installing malicious software extensions. The Cursor, Windsurf, and Google Antigravity AI IDEs, with over a million users combined, were found recommending extensions that …

New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed …

New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications. The attack combines vishing (voice phishing), spoofed domains, and Google’s own trusted infrastructure to achieve exceptional success …

Threat Actors Allegedly Promoting New ‘Brutus’ Brute-Force Tool Targeting Fortinet Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor operating under the moniker “RedTeam” has begun advertising a new brute-force attack tool, “Brutus,” designed to target Fortinet services, according to recent dark web intelligence. The tool is priced at $1,500, signaling growing interest in automated credential-stuffing …

Top 20 Best Endpoint Management Tools – 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Endpoint management has become essential for modern IT, securing and optimizing devices across hybrid and remote environments. With distributed workforces expanding, demand for robust endpoint management tools reaches new heights in 2026. This guide ranks the top 20 endpoint management …

Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. A threat actor operating under the nickname “Zestix” and his alias “Sentap” has been systematically accessing corporate cloud …

Stealthy Tuoni C2 Malware Targets Major U.S. Real Estate Firm with AI-Enhanced Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have shifted their approach to infiltration. Rather than launching quick attacks, they now work silently within networks, stealing important information, and waiting weeks or months before striking. This is exactly what happened in a recent attack discovered by Morphisec …

$35M Cryptocurrency Theft Linked to LastPass Password Manager DataBreach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Blockchain intelligence firm TRM Labs has traced over $35 million in stolen cryptocurrency to the 2022 LastPass breach, revealing a sophisticated Russian cybercriminal laundering operation that remains active into 2025. In 2022, hackers breached LastPass and stole encrypted password vaults …