Hackers Allegedly Selling Exploit for Windows Remote Desktop Services 0-Day Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor is allegedly selling a zero-day exploit for a Windows Remote Desktop Services privilege escalation vulnerability, tracked as CVE-2026-21533, for a staggering $220,000 on a dark web forum. This highly priced exploit targets improper privilege management to grant …

Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zero-Click Command Injection AVideo Platform Allows Stream Hijacking A critical vulnerability in AVideo, a widely used open-source video hosting and streaming platform. Tracked as CVE-2026-29058, this zero-click flaw carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating …

Cognizant TriZetto Data Breach Exposes Health Information of 3.4 Million Patients

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cognizant TriZetto Data Breach TriZetto Provider Solutions, a healthcare technology subsidiary of the IT services giant Cognizant, has officially disclosed a massive cybersecurity data breach affecting the sensitive health information of 3,433,965 patients. The healthcare organization recently filed a formal …

Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious imToken Chrome Extension Socket’s Threat Research Team has discovered a malicious Google Chrome extension named “lmΤoken Chromophore” that actively steals cryptocurrency wallet credentials. Masquerading as a harmless hex color visualizer, the extension actually impersonates the popular non-custodial wallet brand …

OpenAI Launches Codex Security that Discover, Validate and Patch Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI Launches Codex Security OpenAI has announced the launch of Codex Security, an application security agent engineered to autonomously identify, validate, and remediate complex vulnerabilities within enterprise and open-source codebases. Formerly known as Aardvark, the tool leverages frontier AI models …

New ClickFix Attack leverages Windows Terminal for Payload Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a new wave of ClickFix attacks that now exploit Windows Terminal to deliver malicious payloads directly onto victim machines. Unlike earlier iterations of this social engineering technique, which relied on the Windows Run dialog, this latest …

RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remote Monitoring and Management (RMM) tools are the backbone of modern IT operations. Security professionals rely on them daily to patch systems, troubleshoot issues, and manage entire networks from anywhere. These tools deliver speed, control, and convenience — qualities every …

FBI Investigates Hack on its Wiretap and Critical Surveillance Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FBI Investigates Hack The Federal Bureau of Investigation has confirmed a cybersecurity incident targeting a sensitive internal network used to manage wiretapping operations and foreign intelligence surveillance warrants, raising serious concerns among national security officials about the potential exposure of …

Microsoft 365 Outage Hits North America as CDN Misconfiguration Disrupts Multiple Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 Outage Hits North America Microsoft is actively investigating a service disruption affecting multiple Microsoft 365 products for users in the North American region, with engineers pointing to Content Delivery Network (CDN) configuration issues as the likely root cause. …

China-Nexus Hackers Attacking Telecommunication Providers With New Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A China-linked advanced persistent threat actor has been actively targeting telecommunications providers across South America since 2024, deploying three new malware implants to gain deep access into critical network infrastructure. The group, tracked as UAT-9244, operates against both Windows and …