Turla’s Kazuar v3 Loader Leverages Event Tracing for Windows and Bypasses Antimalware Scan Interface

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Turla, a sophisticated threat actor known for targeted cyber attacks, has deployed an upgraded version of its Kazuar v3 loader that introduces advanced evasion techniques designed to bypass modern security …

Microsoft and Authorities Dismatles BEC Attack Chain Powered by RedVDS Fraud Engine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint operation led by Microsoft and international law enforcement has dismantled a business email compromise (BEC) attack chain powered by the RedVDS fraud engine. RedVDS operated as a low‑cost …

Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack any User Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in Cal.com’s scheduling platform enables attackers to hijack any user account by exploiting a flaw in the NextAuth JWT callback mechanism. Tracked as CVE-2026-23478, this …

HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett Packard Enterprise (HPE) has disclosed four high-severity vulnerabilities in its Aruba Networking Instant On devices that could allow attackers to access sensitive network information and disrupt operations. The security …

Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights …

Palo Alto Networks Firewall Vulnerability Allows Unauthenticated Attackers to Trigger Denial of Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has patched a critical denial-of-service vulnerability in its PAN-OS firewall software, tracked as CVE-2026-0227, which lets unauthenticated attackers disrupt GlobalProtect gateways and portals. The flaw carries a …

Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system …

Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware loader known as CastleLoader has emerged as a critical threat to US government agencies and critical infrastructure organizations. First identified in early 2025, this stealthy malware has …

Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, …

New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel single-click attack targeting Microsoft Copilot Personal that enables attackers to silently exfiltrate sensitive user data. The vulnerability, now patched, allowed threat actors to hijack sessions via a phishing …