Check Point Harmony SASE Windows Client Vulnerability Enables Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical privilege-escalation vulnerability has been discovered in Check Point’s Harmony SASE (Secure Access Service Edge) Windows client software, affecting versions prior to 12.2. Tracked as CVE-2025-9142, the flaw allows local attackers to write or delete files outside the intended certificate working …

SoundCloud Data Breach Exposes 29.8 Million Personal users Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, music streaming platform SoundCloud disclosed a significant data breach affecting approximately 29.8 million user accounts. The unauthorized access compromised personally identifiable information (PII), including email addresses, usernames, display names, avatars, follower statistics, and geographic location data. The …

Chrome Security Update Patches Background Fetch API Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chrome versions 144.0.7559.109 and 144.0.7559.110 have been released to the stable channel, addressing a critical security vulnerability in the Background Fetch API. The update is rolling out across Windows, Mac, and Linux systems over the coming days and weeks, making …

Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has confirmed a critical authentication bypass vulnerability in its FortiCloud SSO feature, actively exploited in the wild under CVE-2026-24858. According to an advisory published on January 27, 2026, the flaw affects FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. With a CVSSv3 …

Nike Investigating Data Breach Following WorldLeaks Ransomware Group Claim

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sportswear giant Nike is actively investigating a potential cybersecurity incident after WorldLeaks, a financially motivated ransomware group, claimed responsibility for a significant data breach affecting the company. The group announced the breach on its darknet leak site on January 22, …

WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has strongly denied a new class-action lawsuit accusing Meta of secretly accessing users’ end-to-end encrypted messages, labeling the claims as false and baseless. The messaging giant reiterated that messages remain private through device-based encryption via the open-source Signal protocol. …

Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese national named Jingliang Su has been sentenced to 46 months in prison for his involvement in a major cryptocurrency fraud scheme targeting American investors. On January 27, 2026, federal courts ordered Su to serve his sentence and pay …

Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered campaign demonstrates a sophisticated approach to delivering information-stealing malware through a combination of social engineering and legitimate Windows components. The attack begins with a deceptive CAPTCHA prompt that tricks users into executing commands manually through the Windows …

WhatsApp New Strict Account Settings Option to Protect Your Account from Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has introduced Strict Account Settings, a lockdown-style security feature designed to protect users from highly sophisticated cyber-attacks. The new privacy feature is specifically tailored for individuals who may be targets of advanced threats, including journalists, activists, and public figures …

HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital …