Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero‑day vulnerability in Gemini MCP Tool exposes users to remote code execution (RCE) attacks without any authentication. Tracked as ZDI‑26‑021 / ZDI‑CAN‑27783 and assigned CVE‑2026‑0755, the flaw carries …

Check Point Harmony SASE Windows Client Vulnerability Enables Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege-escalation vulnerability has been discovered in Check Point’s Harmony SASE (Secure Access Service Edge) Windows client software, affecting versions prior to 12.2. Tracked as CVE-2025-9142, the flaw allows local attackers …

SoundCloud Data Breach Exposes 29.8 Million Personal users Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, music streaming platform SoundCloud disclosed a significant data breach affecting approximately 29.8 million user accounts. The unauthorized access compromised personally identifiable information (PII), including email addresses, usernames, …

Chrome Security Update Patches Background Fetch API Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome versions 144.0.7559.109 and 144.0.7559.110 have been released to the stable channel, addressing a critical security vulnerability in the Background Fetch API. The update is rolling out across Windows, Mac, …

Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has confirmed a critical authentication bypass vulnerability in its FortiCloud SSO feature, actively exploited in the wild under CVE-2026-24858. According to an advisory published on January 27, 2026, the …

Nike Investigating Data Breach Following WorldLeaks Ransomware Group Claim

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sportswear giant Nike is actively investigating a potential cybersecurity incident after WorldLeaks, a financially motivated ransomware group, claimed responsibility for a significant data breach affecting the company. The group announced …

WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has strongly denied a new class-action lawsuit accusing Meta of secretly accessing users’ end-to-end encrypted messages, labeling the claims as false and baseless. The messaging giant reiterated that messages …

Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese national named Jingliang Su has been sentenced to 46 months in prison for his involvement in a major cryptocurrency fraud scheme targeting American investors. On January 27, 2026, …

Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered campaign demonstrates a sophisticated approach to delivering information-stealing malware through a combination of social engineering and legitimate Windows components. The attack begins with a deceptive CAPTCHA prompt …