Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js has updated its HackerOne vulnerability disclosure program to require a minimum Signal score of 1.0, aiming to reduce low-quality submissions and improve processing efficiency. Node.js has implemented a new …

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security feature for Teams Calling now alerts users to suspicious external calls that try to impersonate trusted organizations. The feature will begin deployment in mid-February 2026 for Targeted …

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass vulnerability, with a new automated campaign targeting even fully patched FortiGate devices. Cybersecurity firm Arctic Wolf first observed the attacks …

New Windows Notepad and Paint Update Brings More Useful AI Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence (AI) features have been added to Windows 11 Notepad and Paint for Canary and Dev Channel users, turning them into cloud-connected tools that require sign-in. The Notepad update …

TrustAsia Revoked 143 Certificates Following LiteSSL ACME Service Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TrustAsia has revoked 143 SSL/TLS certificates following the discovery of a vulnerability in its LiteSSL ACME service. The flaw allowed for the improper reuse of domain validation data across different …

HPE Alletra and Nimble Storage Vulnerability Grants Admin Access to Remote Attacker

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability affecting multiple storage platforms could allow remote attackers to gain administrative access without physical interaction. The flaw, tracked as CVE-2026-23594, impacts HPE Alletra 6000, Alletra …

North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea–aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a …

New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s January 2026 Windows 11 security update KB5074109 has triggered multiple system stability issues, including lockups and black screens, prompting users to uninstall it. Reports highlight graphics regressions and app …

ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP Penetration Testing Kit (PTK) browser extension directly into ZAP-launched browsers. This streamlines …