Kimwolf Botnet Swamps Anonymity Network I2P

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

For the past week, the massive “Internet of Things” (IoT) botnet known as Kimwolf has been disrupting The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users started reporting disruptions in …

Legacy IRC Botnet Campaign Uses Automated SSH Compromise Pipeline to Enroll Linux Hosts at Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSHStalker is a newly discovered Linux botnet that brings back Internet Relay Chat (IRC) control while using automation to compromise servers over SSH. It mainly succeeds by guessing weak or reused passwords, then turning each host into a launchpad for …

GitGuardian Raises $50M Series C to Address Non-Human Identities Crisis and AI Agent Security Gap

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, NY, February 11th, 2026, CyberNewswire Insight Partners leads round, alongside Quadrille Capital, to accelerate expansion across Americas, EMEA, and strategic verticals GitGuardian, a leading secrets and Non-Human Identity (NHI) security platform and #1 app on GitHub Marketplace, today …

MSHTML Framework 0-Day Vulnerability Let Attackers Security Feature over Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MSHTML Framework 0-Day Vulnerability Microsoft has released an urgent security patch for a critical zero-day vulnerability (CVE-2026-21513) affecting the MSHTML Framework, which was actively exploited in the wild before a fix became available. The flaw allows attackers to bypass Windows …

Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Office Word 0-day Vulnerability A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections. This flaw has been actively exploited in the wild and carries a …

Cephalus Ransomware Emerges as Go-Based Double-Extortion Threat Targeting Exposed RDP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cephalus has surfaced as a Go-built ransomware strain linked to victim activity as early as June 2025, with wider public reporting appearing in August. It focuses on Windows networks and follows a double-extortion playbook, stealing sensitive data before it locks …

Microsoft Investigates Teams Assignment Errors After Failed Service Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Investigates Teams Assignment Errors Microsoft Teams faces widespread disruptions in assignment management, prompting an urgent investigation by the company. Users of Microsoft Teams are encountering error messages when trying to open, set, or delete assignments. The issue stems from …

CISA Adds Six Microsoft 0-Day Vulnerabilities to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 0-Day Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urgently expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding six zero-day vulnerabilities, all affecting Microsoft products. This move underscores escalating threats from nation-state actors and cybercriminals actively …

Coinbase Cartel Targets High-Value Sectors with Data-Theft-First Extortion Strategy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape continues to evolve with new threat actors adopting unconventional tactics. Coinbase Cartel emerged in September 2025, quickly claiming 14 victims in its first month of operation. Unlike traditional ransomware groups, this threat actor focuses exclusively on data …

Windows Remote Access Connection Manager 0-Day Vulnerability Let Attackers Trigger DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Remote Access Connection Manager 0-Day Vulnerability Microsoft has patched a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, tracked as CVE-2026-21525, which allowed attackers to trigger denial-of-service (DoS) conditions on unpatched systems. The flaw, stemming from …