Paloalto Cortex XDR Broker Vulnerability Attackers to Obtain and Modify Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paloalto Cortex XDR Broker Vulnerability A security advisory has been issued for a newly discovered vulnerability affecting the Cortex XDR Broker Virtual Machine (VM). This flaw could allow a highly privileged, authenticated attacker to access and alter sensitive system information. …

Ericsson US Discloses Data Breach – Hackers Stolen Employees and Customers Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ericsson Data Breach The U.S. subsidiary of a Swedish telecommunications multinational has disclosed a data breach exposing the personal information of employees and customers. The incident did not occur on Ericsson’s internal network, but rather targeted one of the company’s …

Cisco IOS XR Software Vulnerability Allow Attacker to Execute Commands as Root

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

cisco-ios-xr-software-vulnerability Cisco has issued a high-severity security advisory warning organizations about two critical privilege-escalation vulnerabilities in its IOS XR Software. If exploited, these flaws could allow an authenticated, local attacker to execute arbitrary commands as root or gain full administrative …

Splunk RCE Vulnerability Allows Attackers to Execute Arbitrary Shell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk RCE Vulnerability A critical security advisory has been released, warning users of a high-severity vulnerability affecting both Enterprise and Cloud platforms. Tracked as CVE-2026-20163, this flaw carries a CVSS score of 8.0. It enables attackers to perform Remote Command …

SolarWinds Web Help Desk Deserialization Vulnerability Enables Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity authorities have flagged a severe security flaw in SolarWinds Web Help Desk that requires immediate attention from system administrators. Tracked as CVE-2025-26399, this vulnerability allows malicious actors to execute unauthorized commands directly on the host machine. Because of its …

Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Office Vulnerability On March 10, 2026, Microsoft released security updates to address a critical vulnerability in its widely used Office suite. Tracked as CVE-2026-26110, this security flaw allows an unauthorized attacker to execute malicious code on a victim’s device. …

GitLab Security Update – Patch for XSS and API DoS Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab Security Update Patch XSS and API DoS Vulnerabilities GitLab has released urgent security updates for its Community Edition (CE) and Enterprise Edition (EE) to address a wide range of vulnerabilities. The newly released versions 18.9.2, 18.8.6, and 18.7.6 fix …

Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Microsoft 365 credential harvesting campaign that weaponizes Cloudflare’s own protective features to evade detection and silently steal user login data. The campaign demonstrates a growing and troubling trend: threat actors turning the very tools designed to defend websites …

Chrome Security Update – Patch for 29 Vulnerabilities that Allows Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome Security Update Patch for 29 Vulnerabilities Google has officially released Chrome version 146 to the stable channel, delivering crucial security updates for Windows, Mac, and Linux users. Rolling out over the coming days, Chrome 146.0.7680.71 for Linux and 146.0.7680.71/72 …

Google Completes Acquisition of Wiz in Historic $32 Billion Deal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially closed its $32 billion all-cash acquisition of Wiz, the Israeli cloud and AI security platform, marking the largest deal in Google’s history and a landmark moment for the global cybersecurity industry. The Wiz team will join Google …