Flickr Confirms Data Breach – 35 million Users Data at Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Flickr Data breach Flickr has disclosed a potential data breach stemming from a vulnerability in a third-party email service provider’s system. The incident, reported on February 5, 2026, may have exposed data for some of its 35 million monthly users, …

Phishing and OAuth Token Flaws Lead to Full Microsoft 365 Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Modern web applications frequently introduce unforeseen attack surfaces through seemingly harmless features designed for user engagement, such as newsletter signups, contact forms, and password resets. While individual vulnerabilities might appear manageable in isolation, sophisticated adversaries increasingly chain these minor flaws …

Dutch Authorities Seized Servers of Windscribe VPN Provider

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windscribe VPN Server Seized Dutch authorities seized a Windscribe VPN server located in the Netherlands as part of an undisclosed investigation. The Canadian provider quickly highlighted how its privacy-focused design thwarted any data recovery efforts. Windscribe disclosed the incident via …

Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity threats are constantly evolving, and a recent campaign highlights a deceptive new tactic where attackers leverage Windows screensaver (.scr) files to compromise systems. This method allows threat actors to deploy legitimate Remote Monitoring and Management (RMM) tools, granting them …

New Epstein Tool Searches LinkedIn Connections Against 3.5 Million Pages Epstein Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Epstein Tool A new open-source Python tool named EpsteIn enables users to check if their LinkedIn connections appear in over 3.5 million pages of Jeffrey Epstein court documents recently released by the U.S. Department of Justice. Developed by Christopher Finke, …

Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security teams have discovered an active spam campaign that uses fake PDF documents to trick users into installing remote monitoring and management (RMM) software. The campaign targets organizations by sending emails containing PDF attachments that appear to be invoices, receipts, …

New CentOS 9 Vulnerability Lets Attackers Escalate to Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CentOS 9 Vulnerability A critical use-after-free (UAF) vulnerability in the Linux kernel’s sch_cake queuing discipline (Qdisc) affects CentOS 9, allowing local users to gain root privileges. Security firm SSD Secure Disclosure published details on February 5, 2026, noting the flaw …

Betterment Data Breach Exposes 1.4 million Customers Personal Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Betterment Data Breach Betterment has disclosed a social engineering–driven data breach that exposed personal information for approximately 1.4 million customer accounts, significantly expanding the fallout from a January 2026 security incident tied to fraudulent crypto scam messages. In early January …

Attackers Mimic RTO Challan Notifications to Deliver Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign targeting Indian users has emerged, disguising itself as legitimate Regional Transport Office (RTO) challan notifications. The malicious applications are distributed outside the Google Play Store, primarily through WhatsApp and similar messaging platforms, exploiting user trust …

ShadowSyndicate Using Server Transition Technique in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ShadowSyndicate, a malicious activity cluster first identified in 2022, has evolved its infrastructure management techniques by adopting a server transition method that allows the threat actor to rotate SSH keys across multiple servers. This new approach makes it harder for …