New Magecart Attack Inject Malicious JavaScript to Skim Payment Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Magecart-style campaign has emerged, targeting online shoppers through malicious JavaScript code designed to steal payment information directly from ecommerce websites. The attack works by injecting hidden scripts into compromised shopping sites, allowing attackers to intercept sensitive data when …

Alleged Ransomware Attack on Apple’s Second-Largest Manufacturer Luxshare – Confidential Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A ransomware attack has reportedly exposed confidential internal documents at a major electronics manufacturer. The breach compromises the company’s critical role in Apple’s global supply chain, including AirPods manufacturing, iPhone production, and Vision Pro assembly. Threat actors have published internal …

ErrTraffic Fueling ClickFix by Breaking the Page Visually and Turns Attack to GlitchFix

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new social engineering technique called GlitchFix has emerged, powered by ErrTraffic—a specialized traffic distribution system designed to trick website visitors into downloading malware through visually broken web pages. The attack platform costs around $800 and offers cybercriminals a complete …

Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE). The patches resolve issues ranging from high-severity authentication flaws to denial-of-service conditions affecting core platform functionality. Critical 2FA Bypass …

LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert regarding an active phishing campaign that commenced on January 19, 2026. The malicious actors are impersonating LastPass support staff and sending fraudulent emails claiming urgent vault backup requirements to harvest master passwords from unsuspecting users. The …

AI Phishing Is Your Company’s Biggest Security Risk in 2026: Here’s How to Stop It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing used to be easy to spot. Bad grammar, strange links, obvious scams. That version is gone.  In 2026, phishing is polished, well-written, and often smarter than it has any right to be thanks to AI. These attacks look like real business emails, slip past …

NVIDIA NSIGHT Graphics for Linux Vulnerability Allows Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent security update addressing a critical vulnerability in NSIGHT Graphics for Linux that could allow attackers to execute arbitrary code on affected systems. The flaw, tracked as CVE-2025-33206, has been rated as High severity with a CVSS score of …

Threat Actors Hiding stealthy PURELOGS Payload Within a Weaponized PNG File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered attack campaign has exposed a sophisticated delivery method for the PURELOGS infostealer, a commodity malware sold as a service on underground forums. Threat actors are using weaponized PNG files hosted on legitimate infrastructure to deliver the payload …

Oracle Critical Security Patch – 337 Vulnerabilities Patched Across Product Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A January 2026 Critical Patch Update addressing 337 new security vulnerabilities spanning multiple product families, marking a comprehensive security initiative to mitigate widespread risk across enterprise systems. The patch encompasses critical fixes for Oracle’s extensive product ecosystem, including database systems, …

Multiple 0-day Vulnerabilities in Anthropic Git MCP Server Enables Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three zero-day vulnerabilities in mcp-server-git, the reference implementation of Git integration for the Model Context Protocol (MCP). The flaws stem from insufficient input validation and argument sanitization in core Git operations. Through prompt injection, attackers can execute code, delete files, …