CISA Warns of Cisco Secure Firewall Management Center 0-Day Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Cisco Secure Firewall Management Center 0-Day Exploit An urgent warning highlights a critical zero-day in Cisco products, now added to the CISA Known Exploited Vulnerabilities Catalog after active …

Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attackers have widened their approach to defeating endpoint security, moving well past the technique of exploiting vulnerable drivers. For years, the Bring Your Own Vulnerable Driver (BYOVD) method was …

Critical Jenkins Vulnerabilities Expose CI/CD Servers to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jenkins Vulnerabilities Expose CI/CD Servers A critical security advisory addressing multiple high-severity vulnerabilities in Jenkins core and the LoadNinja plugin. Issued on March 18, 2026, the alert warns that these …

Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Navia Data Breach A prominent U.S. consumer-focused benefits administrator has disclosed a significant data breach exposing the sensitive personal and health information of approximately 2.7 million individuals.​ On January 23, …

Bamboo Data Center and Server Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bamboo Data Center and Server Vulnerability A high-severity security flaw has been addressed in Bamboo Data Center, an enterprise platform widely used for software build and release management. Tracked as …

New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered infostealer malware named Speagle has emerged as a serious threat targeting organizations that run Cobra DocGuard, a document security and encryption platform developed by Chinese company EsafeNet. …

Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apex AI Penetration Testing Agent Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, …

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to …

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive …

Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities Disrupts IoT Botnet Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets. The U.S. Justice Department, collaborating closely with Canadian and German …