Multiple 0-day Vulnerabilities in Anthropic Git MCP Server Enables Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three zero-day vulnerabilities in mcp-server-git, the reference implementation of Git integration for the Model Context Protocol (MCP). The flaws stem from insufficient input validation and argument sanitization in core Git …

Beware of Weaponized Shipping Documents that Deliver Remcos RAT with a Wide Range of Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging a dangerous new campaign that weaponizes ordinary-looking shipping documents to distribute Remcos, a powerful remote access trojan. This phishing scheme uses fake shipping emails as the …

Hackers Extensively Abuses Visual Studio Code to Execute Malicious Payloads on Victim System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors linked to North Korea have continued to expand their attack capabilities by weaponizing Microsoft Visual Studio Code, one of the world’s most popular code editors. The Contagious Interview …

Microsoft Teams External Domain Anomalies Allow Defenders to Detect Attackers at Earliest

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is rolling out a new security feature called the External Domains Anomalies Report for Teams, designed to help IT administrators identify and respond to suspicious external communications before they …

Google Chrome 144 Update Patches High-Severity V8 Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Stable-channel release of Chrome version 144 addresses a high-severity vulnerability in the V8 JavaScript engine. The update, version 144.0.7559.96/.97 for Windows and Mac and 144.0.7559.96 for Linux, began …

Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root”

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote authentication bypass vulnerability has been disclosed in GNU InetUtils affecting the telnetd server component. The flaw, reported by a security researcher on January 19, 2026, allows unauthenticated …

Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign is actively exploiting LinkedIn’s trusted social media platform to distribute a dangerous remote access trojan to corporate employees. Attackers are leveraging the professional credibility of LinkedIn …

Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has disclosed a severe security vulnerability affecting its Fusion Middleware suite, specifically targeting the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Assigned CVE-2026-21962, this flaw carries …

Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical architectural flaw in Microsoft Azure’s Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations …

CISA Releases BRICKSTORM Malware Report with New YARA Rules for VMware vSphere

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency has issued a malware analysis report on BRICKSTORM, a sophisticated backdoor linked to Chinese state-sponsored cyber operations. Released in December 2025 and updated through …