Microsoft Patch Tuesday February 2026 – 54 Vulnerabilities Fixed, Including 6 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Patch Tuesday February 2026 Microsoft released its February 2026 Patch Tuesday updates on February 10, addressing 54 vulnerabilities, including six zero-days across Windows, Office, Azure, and developer tools. The updates fix issues in products like Windows Remote Desktop Services, …

FortiSandbox XSS Vulnerability Let Attackers Run Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiSandbox XSS Vulnerability Fortinet has disclosed a high-severity cross-site scripting (XSS) vulnerability in its FortiSandbox platform, tracked as CVE-2025-52436 (FG-IR-25-093), that enables unauthenticated attackers to execute arbitrary commands on affected systems. Dubbed an “Improper Neutralization of Input During Web Page …

Threat Hunting Is Critical to SOC Maturity but Often Misses Real Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat Hunting Is Critical to SOC High-performing SOC teams are increasingly turning to sandbox-derived threat intelligence to make threat hunting repeatable and impactful. Tools like ANY.RUN’s TI Lookup enables faster hunts grounded in real attacker behaviours from millions of analyses. …

FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiOS Authentication Bypass Vulnerability Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN or Fortinet Single Sign-On (FSSO) policies. Classified under CWE-305 (Authentication …

APT36 Hacker Group Attacking Linux Systems with New Tools to Disturb Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

For more than a decade, Indian government and defense organizations have operated under a constant digital shadow. A tightly connected espionage ecosystem, primarily involving the Transparent Tribe (APT36) group and the aligned SideCopy cluster, has continued to probe and adapt. …

Threat Actors Weaponizes Bing Ads Attack Users with Azure Tech Support Scams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated tech support scam campaign has emerged, exploiting Bing search advertisements to redirect unsuspecting users to fraudulent pages hosted on Microsoft Azure Blob Storage. This operation has affected users across 48 different organizations in the United States, impacting sectors …

UNC1069 Hackers Attacking Finance Sector with New Tools and AI-Enabled Social Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors, tracked as UNC1069, have intensified their attacks on the cryptocurrency and finance sectors using a sophisticated blend of novel malware and artificial intelligence. Active since at least 2018, this financially motivated group continues to evolve its …

Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

React2Shell Vulnerability AI-Generated Malware A fully AI-generated malware campaign actively exploiting the “React2Shell” vulnerability, detected within Darktrace’s “CloudyPots” global honeypot network, the intrusion highlights a critical shift in cybercrime: the weaponization of Large Language Models (LLMs) to lower the barrier …

VoidLink Linux C2 Highlights LLM-Generated Malware with Multi-Cloud and Kernel-Level Stealth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Linux malware framework known as VoidLink has emerged as a concerning example of AI-assisted threat development, combining advanced multi-cloud targeting capabilities with kernel-level stealth mechanisms. The malware represents a new generation of cyber threats where large language models …

Attackers Weaponizing Windows Shortcut File to Deliver Global Group Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cyber threat landscape is witnessing the resurgence of the Phorpiex botnet, a long-standing malware-as-a-service platform active for over a decade. In a recent high-volume campaign, attackers are distributing phishing emails with the deceptive subject line “Your Document.” These emails …