CISA Warns of FortiCloud SSO Authentication Bypass Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical authentication bypass vulnerability in multiple Fortinet products, actively exploited in the wild. Tracked as CVE-2026-24858, the flaw allows attackers with a FortiCloud account to hijack …

Google Disrupted World’s Largest IPIDEA Residential Proxy Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google and its partners launched a major operation this week to shut down what security experts consider one of the world’s largest residential proxy networks: IPIDEA. The proxy service operates by routing internet traffic through millions of everyday consumer devices …

Microsoft 365 Outlook Add-ins Weaponized to Exfiltrate Sensitive Email Data Without Leaving Traces

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant architectural blind spot in the Microsoft 365 ecosystem that allows threat actors to exfiltrate sensitive email data without leaving forensic traces. Dubbed “Exfil Out&Look,” this attack technique leverages the Outlook add-in framework to intercept outgoing communications stealthily. Unlike …

Cal.com Broken Access Controls Exposes Millions of Bookings and Leads to Complete Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cal.com, an open-source scheduling platform that millions of people use to book meetings and manage their calendars, recently faced a serious security problem. The platform provides an alternative to tools like Calendly, offering features like calendar syncing, team scheduling, and …

eSkimming Attacks Fuelled with Persistent Threats, Evolving Tactics, and Unfinished Recovery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

eSkimming attacks, commonly known as Magecart attacks, continue to plague e-commerce websites across the globe, stealing payment card data from unsuspecting customers at checkout. These malicious campaigns inject JavaScript code into compromised websites, capturing sensitive financial information as users complete …

Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Vietnamese cybercrime group is using artificial intelligence to write malicious code in an ongoing phishing campaign that distributes the PureRAT malware through fake job opportunities. The campaign, initially detected in December 2025, represents a concerning evolution in threat actor …

BlackIce – A Container Based Red Teaming Toolkit for AI Security Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Databricks has officially announced the release of BlackIce, an open-source, containerized toolkit designed to streamline AI security testing and Red Teaming. Originally introduced at CAMLIS Red 2025, BlackIce addresses the fragmentation and configuration challenges that security researchers often face when …

Critical IDIS IP Cameras One-Click Vulnerability Leads to full Compromise of Victim’s Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security flaw in IDIS IP cameras has emerged, allowing attackers to gain complete control over a victim’s computer with just one click. The vulnerability, tracked as CVE-2025-12556, targets the IDIS Cloud Manager (ICM) Viewer, a Windows-based application used …

eScan Antivirus Update Server Hacked to Push Malicious Update packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical supply chain compromise affecting MicroWorld Technologies’ eScan antivirus product, wherein threat actors successfully hijacked the vendor’s legitimate update infrastructure to distribute malware. Discovered on January 20, 2026, by Morphisec, the attack utilized a trojanized update package to deploy …

Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. The change targets one of the oldest and weakest ways to sign in to email systems, …