Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage. That’s a Business Problem 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security Operations Centers live or die by their ability to respond quickly and accurately to alerts. At the heart of this process is alert triage — the initial evaluation that decides whether an alert is a real incident, a false positive, or something that needs immediate …

Hackers are Leveraging SEO Poisoning to Attack Users Looking for Legitimate Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have adopted a deceptive strategy to compromise users searching for common software applications online. These attackers are using search engine optimization poisoning techniques to place malicious links at the top of search results. When unsuspecting users click on these …

MEDUSA Security Testing Tool With 74 Scanners and 180+ AI Agent Security Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MEDUSA, an AI-first Static Application Security Testing (SAST) tool boasting 74 specialized scanners and over 180 AI agent security rules. This open-source CLI scanner targets modern development challenges like false positives and multi-language coverage. MEDUSA consolidates security scanning across 42+ …

6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 6,000 SmarterMail servers exposed on the internet are running vulnerable versions that are at risk of active remote code execution (RCE) attacks. Security researchers identified the flaws through daily HTTP vulnerability scans, and exploitation attempts have already been observed …

New Deepfake Phishing Attack Via Zoom or Microsoft Teams Call Attacking Bitcoin Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous phishing campaign is targeting cryptocurrency holders through video calls that use artificial intelligence to create fake versions of trusted contacts. The attack spreads through Telegram and relies on Zoom or Microsoft Teams to deliver convincing deepfake videos that …

Node.js 25.5.0 Released Update Root Certificates and New Command-Line Flags

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js version 25.5.0 was released on January 26, 2026, introducing significant developer-focused enhancements and security updates. The release prioritizes simplified application packaging through a new command-line flag while maintaining cryptographic security standards through updated certificate authorities. The most significant developer …

CISA releases Secure Connectivity Principles Checklist for Operational Technology Networks Connectivity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC-UK) have jointly released comprehensive guidance on Secure Connectivity Principles for Operational Technology (OT) environments. Published on January 14, 2026, this framework addresses mounting pressures …

WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A serious security vulnerability in Western Digital’s WD Discovery desktop application has been disclosed, potentially allowing attackers to execute arbitrary code on Windows systems. The flaw, tracked as CVE-2025-30248, affects WD Discovery version 5.2.730 and all prior releases. The security …

Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Caminho Loader is a new Loader-as-a-Service threat that blends steganography, fileless execution, and cloud abuse to quietly deliver malware across several regions. First seen in March 2025 and believed to originate from Brazil, this service hides .NET payloads inside harmless-looking …

Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the PyPI-distributed version of PLY (Python Lex-Yacc) 3.11, allowing arbitrary code execution through unsafe deserialization of untrusted pickle files. The vulnerability, assigned CVE-2025-56005, affects the undocumented picklefile parameter in the yacc() function, which remains absent from official …