FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiOS Authentication Bypass Vulnerability Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN …

APT36 Hacker Group Attacking Linux Systems with New Tools to Disturb Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

For more than a decade, Indian government and defense organizations have operated under a constant digital shadow. A tightly connected espionage ecosystem, primarily involving the Transparent Tribe (APT36) group and …

Threat Actors Weaponizes Bing Ads Attack Users with Azure Tech Support Scams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated tech support scam campaign has emerged, exploiting Bing search advertisements to redirect unsuspecting users to fraudulent pages hosted on Microsoft Azure Blob Storage. This operation has affected users …

UNC1069 Hackers Attacking Finance Sector with New Tools and AI-Enabled Social Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors, tracked as UNC1069, have intensified their attacks on the cryptocurrency and finance sectors using a sophisticated blend of novel malware and artificial intelligence. Active since at …

Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

React2Shell Vulnerability AI-Generated Malware A fully AI-generated malware campaign actively exploiting the “React2Shell” vulnerability, detected within Darktrace’s “CloudyPots” global honeypot network, the intrusion highlights a critical shift in cybercrime: the …

VoidLink Linux C2 Highlights LLM-Generated Malware with Multi-Cloud and Kernel-Level Stealth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Linux malware framework known as VoidLink has emerged as a concerning example of AI-assisted threat development, combining advanced multi-cloud targeting capabilities with kernel-level stealth mechanisms. The malware represents …

Attackers Weaponizing Windows Shortcut File to Deliver Global Group Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cyber threat landscape is witnessing the resurgence of the Phorpiex botnet, a long-standing malware-as-a-service platform active for over a decade. In a recent high-volume campaign, attackers are distributing phishing …

Crypto Scanner – New Tool to Find Quantum-Vulnerable Cryptography in your Codebase

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Crypto Scanner Tool Find Quantum Vulnerable Cryptography As the timeline for powerful quantum computing accelerates, a new open-source tool has emerged to help developers secure their data against future threats. …

Fancy Bear Hackers Exploiting Microsoft Zero-Day Vulnerability to Deploy Backdoors and Email Stealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russia-linked cyber espionage group known as Fancy Bear has launched Operation Neusploit. The group is also known as APT28. This marks a significant escalation, leveraging a zero-day vulnerability, CVE-2026-21509, …

Axios Vulnerability Let Attackers Triggers DoS Condition and Crash Node.js Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security flaw has been discovered in Axios, one of the most popular HTTP client libraries used in the JavaScript ecosystem. The vulnerability, tracked as CVE-2026-25639, allows remote attackers to trigger …