800K+ GNU InetUtils telnetd Instances Exposed to RCE Attacks – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the telnetd component of GNU Inetutils has exposed approximately 800,000 internet-accessible Telnet instances to unauthenticated remote code execution (RCE). Tracked as CVE-2026-24061 with a CVSS score of 9.8, the flaw allows attackers to gain …

Curl to End Bug Bounty Following Low-Quality AI-Generated Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The curl project ended its bug bounty program in January 2026 because it received too many low-quality and useless bug reports. The decision reflects growing frustration within the open-source security community regarding the unintended consequences of financial incentive structures on …

New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Browser attacks have become far more dangerous and organized than before. A new threat called Stanley, discovered in January 2026, shows just how serious the problem has become. This malware-as-a-service toolkit, priced between $2,000 and $6,000, does something particularly deceptive: …

Lazarus Hackers Actively Attacking European Drone Manufacturing Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus, a sophisticated North Korean-aligned hacking group also known as HIDDEN COBRA, has launched a new wave of targeted attacks against European drone manufacturers and defense contractors. The campaign, tracked as Operation DreamJob, emerged in late March 2025 and specifically …

MITRE Releases New Cybersecurity Framework to Protect the Embedded Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Embedded Systems Threat Matrix™ (ESTM) framework was introduced to help secure embedded systems used in critical infrastructure and defense technologies across the U.S. Developed collaboratively with the Air Force’s Cyber Resiliency Office for Weapon Systems (CROWS). ESTM addresses …

New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea’s Lazarus Group has launched a sophisticated supply chain attack targeting software developers through a campaign called “Fake Font.” The threat actors are using fake job interviews and malicious GitHub repositories to trick engineers into downloading code that contains …

‘SyncFuture’ Campaign Weaponizing Legitimate Enterprise Security Software to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2025, threat researchers uncovered an alarming espionage operation targeting residents of India through sophisticated phishing campaigns. The attack, dubbed SyncFuture, demonstrates how cybercriminals can abuse legitimate business software as a vehicle for launching advanced malware attacks. Attackers sent …

Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A moderate-severity vulnerability in the Hadoop Distributed File System (HDFS) native client could allow attackers to trigger system crashes or corrupt critical data through maliciously crafted URI inputs. The vulnerability, tracked as CVE-2025-27821, affects Apache Hadoop versions 3.2.0 through 3.4.1. …

Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An out-of-band (OOB) cumulative update, KB5078127, to address critical file system compatibility issues affecting Windows 11 users. The update resolves widespread problems introduced by the January 13, 2026, security update (KB5074109) that caused application freezes and cloud storage failures across …

48M Gmail, 6.5M Instagram Exposed Online From Unprotected Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive database containing 149 million stolen login credentials was discovered exposed online without password protection or encryption. Posing serious security risks to users of Gmail, Instagram, Facebook, Netflix, and thousands of other platforms worldwide. The publicly accessible database contained …