CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a sophisticated malware campaign using an unusual but effective tactic: deliberately crashing users’ browsers. The threat, named CrashFix, operates through a malicious Chrome extension disguised as …

Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered significant vulnerabilities in the firmware of Xiaomi’s popular Redmi Buds series, specifically affecting models ranging from the Redmi Buds 3 Pro up to the latest Redmi …

BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in ServiceNow’s Virtual Agent API and the Now Assist AI Agents application has been discovered, allowing unauthenticated attackers to impersonate any user and execute privileged AI agents …

Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band emergency update to resolve a critical issue affecting Remote Desktop connections on Windows client devices. The problem emerged immediately following the installation of the January …

Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent …

Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing …

Argus – Python-powered Toolkit for Information Gathering and Reconnaissance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Argus is a comprehensive Python-based toolkit designed for reconnaissance tasks in cybersecurity. The developers recently released version 2.0, expanding it to include 135 modules. This tool consolidates network analysis, web …

Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Vertex AI contains default configurations that allow low-privileged users to escalate privileges by hijacking Service Agent roles. XM Cyber researchers identified two attack vectors in the Vertex AI Agent …

Researchers Gain Access to StealC Malware Command-and-Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor’s identity through their own stolen session cookies. The breach …