Conduent Data Breach – Largest Data Breach in U.S. History As Ransomware Group Stolen 8 TB of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Conduent Data Breach Conduent Data Breach Notification Letters Sent to Millions as Ransomware Group Claims 8 Terabytes Stolen in One of the Largest U.S. Incidents. Letters began reaching affected individuals …

New MIMICRAT Custom RAT Uncovered in Sophisticated Multi-Stage ClickFix Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has been uncovered, utilizing a deceptive technique known as “ClickFix” to distribute a custom remote access trojan dubbed MIMICRAT. This operation compromises legitimate websites to …

Microsoft MFA Down – 504 Gateway Timeout Errors Disrupting MFA Access for U.S. Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a significant service degradation affecting Multi-Factor Authentication (MFA) across its Microsoft 365 suite, with users in the North America region reporting widespread 504 gateway timeout errors …

New Phishing Framework Starkiller Proxies Real Login Pages to Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly sophisticated phishing framework named Starkiller has recently emerged, offering attackers an advanced method to steal credentials and bypass multi-factor authentication. Developed by a group known as Jinkusu, this …

North Korean Threat Actors Leverage Fake IT Worker Campaigns and Contagious Interview Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean nation-state threat actors have been running a two-part operation — posing as job recruiters while embedding fake workers inside real companies. Since at least 2022, these actors have …

PoC Exploit Released for Grandstream GXP1600 VoIP Phones RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Grandstream GXP1600 VoIP Phones RCE Vulnerability A critical zero-day vulnerability, tracked as CVE-2026-2329, is affecting Grandstream’s GXP1600 series VoIP desk phones. The issue is an unauthenticated stack-based buffer overflow that …

jsPDF Vulnerability Exposes Millions of Developers to Object Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

jsPDF Vulnerability Injection Attacks A newly disclosed security flaw in the popular jsPDF library has exposed millions of web developers to PDF Object Injection attacks, allowing remote attackers to embed arbitrary objects and …

CISA Warns of Multiple Roundcube Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has officially updated its Known Exploited Vulnerabilities (KEV) Catalog to include new security flaws affecting a popular webmail platform. On February 20, 2026, the agency added two critical vulnerabilities …

OWASP Smart Contract Top 10 2026 — Security Risks and Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OWASP Smart Contract Top 10 2026 The Open Web Application Security Project (OWASP) has published the Smart Contract Top 10: 2026, a forward-looking standard awareness document designed to arm Web3 …

Google Suspends OpenClaw Users from Antigravity AI After OAuth Token Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Suspends OpenClaw Users Google has suspended access to its Antigravity AI platform for numerous users of the open-source tool OpenClaw, sparking backlash over aggressive enforcement of terms of service …