Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of targeted attacks is quietly hitting Argentina’s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan …

Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has temporarily halted the automatic installation of the Microsoft 365 Copilot app on Windows devices. According to a recent update in the Microsoft 365 Message Center on March 16, 2026, the company paused the mandatory rollout, originally scheduled to …

Researchers Reveal ‘RegPwn,’ a Windows Registry Vulnerability That Granted SYSTEM Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RegPwn Windows Registry Vulnerability A high-severity Windows vulnerability dubbed “RegPwn” (CVE-2026-24291) is an elevation-of-privilege flaw that allows low-privileged users to gain full SYSTEM access. The MDSec red team discovered the vulnerability and successfully used it in internal engagements since January …

Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiClient SQL Injection vulnerability A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS). Tracked as CVE-2026-21643, this severe flaw carries a CVSS score of 9.1. It allows unauthenticated attackers to execute arbitrary SQL commands and access sensitive …

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Local Privilege Escalation (LPE) vulnerability in default installations of Ubuntu Desktop 24.04 and later allows an unprivileged local attacker to gain full root access. Tracked as CVE-2026-3888, uncovered by The Qualys Threat Research Unit, the flaw exploits an unintended …

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Detection and Response Team details a sophisticated voice phishing (vishing) campaign that successfully compromised a corporate environment in November 2025. Unlike conventional intrusions that rely on software exploits, this attack weaponized trust, collaboration platforms, and built-in Windows tooling to …

Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran’s cyber operations took a sharp turn in early 2026, with state-linked threat actors quietly embedding themselves inside US and Canadian networks while also targeting internet-connected surveillance cameras across the Middle East for battlefield intelligence. The Iranian APT group MuddyWater, …

Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape entered a new phase in 2025. Once a highly reliable criminal business model built on encrypting victim files and collecting ransom payments, it is now under significant financial pressure. Ransom payment rates have hit historic lows, …

Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated supply chain attack struck the developer community on March 16, 2026, when a threat actor known as Glassworm backdoored two widely used React Native npm packages, turning them into silent credential and cryptocurrency stealers. The affected packages — [email protected] and [email protected] — …

AWS Bedrock AgentCore Sandbox Bypass Allows Covert C2 Channels and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw in AWS Bedrock AgentCore Code Interpreter’s “Sandbox” network mode, a feature advertised by AWS as providing complete network isolation that allows outbound DNS queries, enabling threat actors to establish covert command-and-control (C2) channels and exfiltrate sensitive …