Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited in the wild, allowing unauthenticated remote attackers to fully bypass authentication and seize administrative …

Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Russian state-sponsored hacking group known as Sandworm has been caught making a calculated pivot from compromised IT networks into operational technology systems that control physical infrastructure. …

Chinese APT Hackers Exploit Microsoft Exchange to Breach Energy Sector Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Chinese state-linked hacking group known as FamousSparrow has quietly infiltrated an Azerbaijani oil and gas company, exploiting an unpatched Microsoft Exchange server to plant multiple backdoors …

New Malware Framework Enables Screen Control, Browser Artifact Access, and UAC Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly uncovered malware framework is raising serious alarms across the cybersecurity community. Researchers have identified a previously unknown implant called TencShell, a sophisticated tool capable of …

Anthropic’s Mythos AI Reportedly Found macOS Vulnerabilities that Could Bypass Apple Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Security researchers at Calif, a Palo Alto-based cybersecurity firm, have used techniques derived from an early version of Anthropic’s secretive Mythos AI model to uncover two previously …

Amazon Quick Bug Exposed AI Chat Agents to Users Blocked by Custom Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Imagine locking your organization’s sensitive data behind a heavy vault door, only to realize the locking mechanism is entirely missing. Security researchers at Fog Security recently uncovered …

New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical vulnerability in the widely used Exim mail server allows unauthenticated attackers to execute arbitrary code and fully compromise exposed servers. Federico Kirschbaum, head of the …