Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities in SolarWinds Web Help Desk (WHD), culminating in unauthenticated remote code execution (RCE) via Java deserialization in CVE-2025-40551, were uncovered by Horizon3.ai researchers. These flaws chain static credentials, security bypasses, and deserialization weaknesses, affecting versions prior to …

Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are increasingly targeting Canadian citizens by abusing their heavy dependence on online government and commercial services. From paying traffic fines and renewing licenses to tracking parcels and booking flights, people now expect these tasks to be quick and digital. …

Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Praetorian Inc. has publicly released Swarmer, a tool enabling low-privilege attackers to achieve stealthy Windows registry persistence by sidestepping Endpoint Detection and Response (EDR) monitoring. Deployed operationally since February 2025, Swarmer exploits mandatory user profiles and the obscure Offline Registry …

New Semantic Chaining Jailbreak Attack Bypasses Grok 4 and Gemini Nano Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Following the recent Echo Chamber Multi-Turn Jailbreak, NeuralTrust researchers have disclosed Semantic Chaining, a potent vulnerability in the safety mechanisms of multimodal AI models like Grok 4 and Gemini Nano Banana Pro. This multi-stage prompting technique evades filters to produce …

Top 10 Best Data Removal Services In 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2026, personal data is no longer just a privacy concern, it is a security vector. With the rise of AI-driven scraping and synthetic identity theft, your digital footprint is being harvested at an unprecedented scale.  Data removal services have evolved from simple “opt-out” tools into …

CISA Chief Uploaded Sensitive Documents into Public ChatGPT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The acting director of the Cybersecurity and Infrastructure Security Agency (CISA) uploaded sensitive contracting documents marked “for official use only” into the public version of ChatGPT last summer, triggering multiple automated security alerts designed to prevent data exfiltration from federal …

Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated supply chain phishing attack, threat actors hijacked an ongoing email thread among C-suite executives discussing a document awaiting final approval. The intruder, posing as a legitimate participant, replied directly with a phishing link mimicking a Microsoft authentication …

TP-Link Archer Vulnerability Let Attackers Take Control Over the Router

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory has been released for a command injection vulnerability affecting the Archer MR600 v5 router. The flaw, tracked as CVE-2025-14756, enables authenticated attackers to execute arbitrary system commands through the device’s admin interface, potentially leading to complete …

Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero‑day vulnerability in Gemini MCP Tool exposes users to remote code execution (RCE) attacks without any authentication. Tracked as ZDI‑26‑021 / ZDI‑CAN‑27783 and assigned CVE‑2026‑0755, the flaw carries a maximum CVSS v3.1 score of 9.8, reflecting its ease …

ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ZAP (Zed Attack Proxy) project, a widely used open-source web application security scanner, has disclosed a critical memory leak in its JavaScript engine. This flaw, likely present for some time, now disrupts active scanning workflows following the introduction of …