Critical JetBrains Vulnerabilities Enable Authentication Bypass and Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 JetBrains has released security updates for a cluster of critical vulnerabilities that enable authentication bypass, account takeover, and remote code execution (RCE) across its on‑premise ecosystem, including Hub, YouTrack, IntelliJ‑based IDEs, Kotlin, GoLand, and TeamCity. These flaws …

Hackers Disable Defender, Sysmon, and WAF Before Dumping Credentials With Mimikatz

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 Hackers have found a new way to blind security teams before stealing passwords, and the technique is as thorough as it is alarming. A threat actor recently disabled Microsoft Defender, killed the Sysmon logging tool, and tore …

CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being exploited in real-world attacks. The vulnerability is a deserialization of …

Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing a legitimate Chrome feature meant for photo editing. The attack …

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. The flaws affect Windows, Linux, and macOS, with the highest …

Medtronic Confirms Data Breach – Hackers Gained Access to Corporate IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 Medical technology giant Medtronic Inc. has disclosed a cybersecurity incident involving unauthorized access to its corporate IT systems, potentially affecting sensitive personal and health-related information of patients using Medtronic medical devices. Medtronic detected unusual activity in certain …

Critical Flaws Double as Elevation of Privilege Dominates the Cyber Threats – Analysis of Microsoft Vulnerabilities Report 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s vulnerability landscape just sent a mixed signal that every security team needs to understand. According to the newly released Microsoft Vulnerabilities Report 2026 — the 13th annual edition published by BeyondTrust — the total number of disclosed Microsoft vulnerabilities …

FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 FortiBleed credential-harvesting campaign, which has compromised more than 430,000 FortiGate firewalls worldwide, is directly feeding two active ransomware-as-a-service operations, INC Ransom and Lynx. SOCRadar’s Threat Research Unit identified an operator with access to FortiBleed infrastructure actively logged …

Alleged Scattered Spider Member Extradited to the US for His Role in Hacking 100+ Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 2, 2026 A dual U.S.-Estonian citizen accused of belonging to the notorious Scattered Spider hacking collective has been extradited from Finland to face federal charges in the Northern District of Illinois, the Department of Justice announced Tuesday. Peter Stokes, …

WhatsApp Username Reservations Go Live – What Are the Security Concerns for 2 Billion Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has begun allowing users to reserve usernames ahead of a broader feature launch planned for later this year, prompting a wave of questions about security, impersonation risk, and account linkage that security researchers should be tracking closely. According to …