Gakido CRLF Injection Vulnerability Let Attackers Bypass Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Gakido, an HTTP client library by HappyHackingSpace, has been discovered that allows attackers to inject arbitrary HTTP headers through CRLF (Carriage Return Line Feed) sequences. Tracked as CVE-2026-24489 under advisory RO-26-005, the vulnerability affects all versions …

Hackers Attacking MongoDB Instances to Delete Database and Add Ransom Note

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively targeting internet-exposed MongoDB instances in large-scale automated ransomware campaigns. The attacks follow a consistent pattern: attackers scan for unsecured MongoDB databases accessible on the public internet, delete the stored data, and insert ransom notes demanding payment …

Arsink Rat Attacking Android Devices to Exfiltrate Sensitive Data and Enable Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Android malware called Arsink RAT has emerged as a serious threat to mobile device security worldwide. This cloud-native Remote Access Trojan gives attackers complete control over infected devices while quietly stealing personal information. The malware spreads through social …

Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ShinyHunters threat group has expanded its extortion operations with sophisticated attack methods targeting cloud-based systems across multiple organizations. These cybercriminals use voice phishing and fake credential harvesting websites to steal login information from employees. Once they gain access, they …

Windows 11 New Security Feature Denies Unauthorized Access to System Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has introduced a significant security control in the latest Windows 11 preview update designed to restrict unauthorized interaction with critical system files. Released as part of the January 2026 non-security preview (KB5074105), this enhancement specifically targets the Storage settings …

1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in OpenClaw, the open-source AI personal assistant trusted by over 100,000 developers, has been discovered and weaponized into a devastating one-click remote code execution exploit. Security researchers at depthfirst General Security Intelligence uncovered a logic flaw that, …

State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic …

Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. …

Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million “users.” Researchers revealed …

AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional PDF reports while emphasizing safe, non-destructive testing. AutoPentestX targets Kali …