LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited in the wild, posing a serious threat to shared hosting environments worldwide. The …

Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise …

Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 16, 2026 Nearly 14,000 internet-facing SimpleHelp servers are exposed following the disclosure of a critical authentication bypass vulnerability tracked as CVE-2026-48558. The flaw raises serious concerns for enterprises using …

Microsoft Site Showing Warning Following Certificate Expiry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Microsoft seems to have failed certificate management after a domain used by sysadmins globally to test connectivity to Microsoft 365 started generating untrusted connection warnings in browsers …

DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 The open-source DPAPISnoop tool has been enhanced to extract CREDHIST entries, enabling offline cracking of historical Windows credentials and deeper insight into password patterns. Lefteris Panos, Security …

SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Threat intelligence sources have reported that the threat actor group SHADOWBYT3$ has allegedly breached Nintendo, claiming to have exfiltrated approximately 859 MB of sensitive internal data. The …

Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Anthropic has updated its privacy policy for Claude, adding explicit terminology that allows the company to perform age and identity verification on consumer users. The change signals …

Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 A critical vulnerability chain in Microsoft 365 Copilot Enterprise that let attackers steal sensitive corporate data, MFA codes, email contents, calendar details, and confidential files with nothing …

Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 Hackers are using Microsoft’s own cloud tools to quietly hunt down payroll and HR staff inside corporate networks, then reroute employee salaries to accounts they control. Security …

China-Nexus Hackers Use Backdoored PAM Modules for Credential Theft and Authentication Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 15, 2026 A sophisticated China-linked threat actor known as Velvet Ant has been running a long-term cyber intrusion inside a major organization’s internal network, going undetected for nearly a …