20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by more than 20,000 active sites. This security flaw allows attackers to create administrator accounts without any authentication, putting thousands of …

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign targeting Windows users has emerged, using deceptive LNK shortcut files to distribute MoonPeak, a dangerous remote access trojan. This malware, which appears to be a variant of XenoRAT, has been linked to threat actors affiliated with …

Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of web-based malware campaigns is using fake verification pages to trick users into installing dangerous software. These attacks copy the look and feel of legitimate security checks that people see every day while browsing the internet. The …

MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated macOS malware called MacSync has emerged as a dangerous new threat targeting cryptocurrency users through deceptive social engineering tactics. The infostealer operates as an affordable Malware-as-a-Service tool designed to harvest sensitive data from macOS systems by convincing victims …

Top 10 Best Data Security Companies in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Data security companies are essential in 2026 for protecting sensitive information amid rising cyber threats and complex cloud environments. In 2026, data security has become a top priority for organizations of all sizes as cyber threats, regulatory pressure, and cloud …

Hackers Can Use GenAI to Change Loaded Clean Page Into Malicious within Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and alarming threat has emerged in the cybersecurity landscape where attackers combine artificial intelligence with web-based attacks to transform innocent-looking webpages into dangerous phishing tools in real time. Security researchers discovered that cybercriminals are now leveraging generative AI …

New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new generation of phishing kits designed specifically for voice-based attacks has emerged as a growing threat to enterprise users across major technology platforms. Okta Threat Intelligence discovered multiple custom phishing kits available on an as-a-service basis that criminals …

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Node.js has updated its HackerOne vulnerability disclosure program to require a minimum Signal score of 1.0, aiming to reduce low-quality submissions and improve processing efficiency. Node.js has implemented a new threshold for vulnerability report submissions through its HackerOne program, mandating …

Microsoft to Add Brand Impersonation Protection Warning to Teams Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security feature for Teams Calling now alerts users to suspicious external calls that try to impersonate trusted organizations. The feature will begin deployment in mid-February 2026 for Targeted Release customers, with general availability timelines to be communicated later. …

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass vulnerability, with a new automated campaign targeting even fully patched FortiGate devices. Cybersecurity firm Arctic Wolf first observed the attacks on January 15, 2026, involving rapid configuration exfiltration and persistence …