WatchGuard VPN Client for Windows Vulnerability Enables Command Execution With SYSTEM Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard VPN Client Windows Vulnerability A security advisory addressing a significant privilege-escalation vulnerability affecting its Mobile VPN with an IPSec client for Windows. The flaw, identified as WGSA-2026-00002, allows local attackers to execute arbitrary commands with SYSTEM-level privileges, potentially granting …

Critical n8n Vulnerability Enables System Command Execution Via Weaponized Workflows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

n8n Vulnerability A critical remote code execution (RCE) vulnerability in n8n, the popular workflow automation platform. This flaw allows authenticated attackers to execute arbitrary system commands on the host server by leveraging weaponized workflows. The vulnerability represents a significant regression …

Microsoft to Add Sysmon Threat Detection Feature Natively to Windows 11

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Add Sysmon Windows 11 A major upgrade has been announced to enhance capabilities for cybersecurity defenders and threat hunters in the Windows ecosystem. With the release of Windows 11 Insider Preview Build 26300.7733 (KB5074178) to the Dev Channel. The …

Cisco Meeting Management Vulnerability Let Remote Attacker Upload Arbitrary Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Meeting Management Vulnerability A high-severity security advisory has been issued for a critical vulnerability in Meeting Management software. This vulnerability allows authenticated remote attackers to upload harmful files and gain complete control over the affected system. The security flaw, …

Beware of Fake Traffic Ticket Portals that Harvest Your PII and Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting Canadian citizens has emerged, using fake traffic ticket payment portals to steal personal and financial information. The attackers employ SEO poisoning techniques to manipulate search engine results, ensuring their fraudulent websites appear legitimate when users …

Hackers Exploit SonicWall SSLVPN Credentials to Deploy EDR Killer and Bypass Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EDR Killer Via SonicWall SSLVPN Threat actors are actively leveraging compromised SonicWall SSLVPN credentials to breach networks and deploy a sophisticated “EDR killer” that can blind endpoint security solutions. In a campaign analyzed by Huntress in early February 2026, attackers …

DragonForce Ransomware Attacking Critical Business to Exfiltrate Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware operation known as DragonForce has emerged as a major threat to organizations worldwide since its appearance in late 2023. This sophisticated malware campaign targets critical business infrastructure across multiple industries, using advanced techniques to encrypt files and …

Beware of Weaponized Voicemail Messages that Allows Hackers to Remote Access to Your System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly shifting tactics toward social engineering to bypass traditional security defenses, catching many users off guard. A sophisticated new campaign dubbed “Voicemail Trap” explicitly targets users with fake voicemail notifications designed to look like routine business communications. These …

APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian state-sponsored actors known as APT28 have initiated a sophisticated cyber espionage campaign targeting high-value government and military entities across Europe. The primary targets include maritime and transport organizations in nations such as Poland, Ukraine, and Turkey. The attackers are …

New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support #Scam Kit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber threat has emerged within the digital advertising ecosystem, specifically targeting users through the vast reach of Facebook’s paid advertising platform. Malicious actors are increasingly weaponizing social media ads to bypass traditional security filters and deliver harmful …