Coinbase Cartel Targets High-Value Sectors with Data-Theft-First Extortion Strategy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware landscape continues to evolve with new threat actors adopting unconventional tactics. Coinbase Cartel emerged in September 2025, quickly claiming 14 victims in its first month of operation. Unlike traditional ransomware groups, this threat actor focuses exclusively on data …

Windows Remote Access Connection Manager 0-Day Vulnerability Let Attackers Trigger DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Remote Access Connection Manager 0-Day Vulnerability Microsoft has patched a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, tracked as CVE-2026-21525, which allowed attackers to trigger denial-of-service (DoS) conditions on unpatched systems. The flaw, stemming from …

Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Socelars Malware Attacking Windows Systems A dangerous information-stealing malware called Socelars is actively targeting Windows systems to collect sensitive authentication data, with particular focus on Facebook Ads Manager accounts and session cookies. Unlike traditional malware that causes immediate system damage, …

Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released Microsoft Patch Tuesday updates to address a critical zero-day vulnerability in Windows Shell that is currently being actively exploited in the wild. Tracked as CVE-2026-21510, this security flaw allows remote attackers to bypass essential protection mechanisms, putting millions of …

GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab Patches Vulnerabilities A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers …

Windows Notepad Vulnerability Allows Attackers to Execute Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Notepad RCE Vulnerability Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday …

Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access. The flaw stems from improper privilege management and was addressed in the February …

Patch Tuesday, February 2026 Edition

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild. Zero-day #1 this month is …

Microsoft Patch Tuesday February 2026 – 54 Vulnerabilities Fixed, Including 6 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Patch Tuesday February 2026 Microsoft released its February 2026 Patch Tuesday updates on February 10, addressing 54 vulnerabilities, including six zero-days across Windows, Office, Azure, and developer tools. The updates fix issues in products like Windows Remote Desktop Services, …

FortiSandbox XSS Vulnerability Let Attackers Run Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiSandbox XSS Vulnerability Fortinet has disclosed a high-severity cross-site scripting (XSS) vulnerability in its FortiSandbox platform, tracked as CVE-2025-52436 (FG-IR-25-093), that enables unauthenticated attackers to execute arbitrary commands on affected systems. Dubbed an “Improper Neutralization of Input During Web Page …