Infostealers Fuel Large‑Scale Brute‑Forcing of Corporate SSO Gateways Using Stolen Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A wave of credential stuffing attacks has exposed a troubling shift in how threat actors are breaking into corporate networks — not by exploiting software vulnerabilities, but by simply logging in with stolen passwords. At the center of this campaign …

FreeBSD Vulnerability Allow Attackers to Crash the Entire System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreeBSD Vulnerability Administrators must urgently patch a critical vulnerability that allows attackers to escape isolated jail environments. Tracked as CVE-2025-15576, the flaw enables a dangerous jailbreak condition despite often being associated with system crashes. It enables a jailed process to …

Critical Zyxel Vulnerabilities Exposes Routers to Remote Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel Vulnerabilities Critical firmware updates have been released to address multiple serious vulnerabilities in networking devices, including 4G LTE/5G NR CPEs, DSL/Ethernet CPEs, Fiber ONTs, Security Routers, and Wireless Extenders. These flaws expose affected routers to remote command injection and …

Juniper Networks PTX Vulnerability Enables Full Router Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major networking vendor has issued an out-of-cycle security bulletin to address a critical vulnerability in its Junos OS Evolved software, specifically affecting PTX Series platforms. This flaw, identified as CVE-2026-21902, allows an unauthenticated, remote attacker to execute arbitrary code …

Microsoft Defender Expands URL Click Alerts to Include Microsoft Teams for Enhanced Security Visibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is strengthening its cybersecurity ecosystem by extending Microsoft Defender for Office 365 (MDO) URL click alerts to Microsoft Teams. Previously focused on email threats, this update gives security teams crucial visibility into potentially malicious activity happening within Teams messages. …

Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a new way to get past users’ defenses — by hiding malware inside gaming tools that look completely normal. Microsoft’s security team has uncovered an active campaign where attackers are distributing trojanized versions of popular gaming utilities …

Claude Code Hacked to Achieve Full RCE and Hijacked Organization API keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Code Hacked RCE Hijacked Organization API keys Critical vulnerabilities in Anthropic’s Claude Code, an AI-powered command-line development tool. The flaws could allow attackers to achieve Remote Code Execution (RCE) and exfiltrate Anthropic API keys by exploiting project configuration files. …

1 Million Records from Dutch Telco Odido Published Online After Extortion Attempt

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Odido Data Breach A major data breach has hit Odido, one of the Netherlands’ prominent telecommunications providers, with cybercriminals publishing over one million customer records online following a failed extortion attempt in February 2026. The threat actor group ShinyHunters is …

Google API Keys Expose Private Data Silently Through Gemini

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege escalation vulnerability affecting Google Cloud API keys specifically how legacy public-facing keys now silently grant unauthorized access to Google’s Gemini AI endpoints, exposing private files, cached data, and billable AI usage to attackers. For over a decade, …

Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered phishing campaign is delivering Agent Tesla, one of the most widely used credential-stealing malware families, through a multi-stage attack chain that leaves almost no trace on a victim’s machine. The campaign uses business-themed phishing emails, obfuscated scripts, …