Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Langchain Community SSRF Bypass Vulnerability A Server‑Side Request Forgery (SSRF) vulnerability has been identified in the langchain/community package, affecting versions up to 1.1.13. The flaw, tracked as CVE‑2026‑26019, has a moderate severity rating, with a CVSS …

25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Password Managers Vulnerability Researchers from ETH Zurich have uncovered 25 serious vulnerabilities in three leading cloud-based password managers: Bitwarden, LastPass, and Dashlane. These flaws enable a malicious server to bypass …

Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. Initially, this malware hid behind deceptive advertisements for fake AI video …

Beware of Fake Shops from Threat Actors to Attack Winter Olympics 2026 Fans

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are targeting fans of the Milano Cortina 2026 Winter Olympics through an extensive network of fake online merchandise stores designed to steal payment information and personal data from unsuspecting …

Single IP Dominates Exploitation Campaign Attacking Ivanti EPMM with RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Single IP Dominates Ivanti EPMM with RCE Vulnerability A critical remote code execution (RCE) flaw in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281, is being heavily exploited. GreyNoise shows …

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Joomla Novarain/Tassos Framework Vulnerabilities Websites running the Novarain/Tassos Framework are vulnerable to critical security flaws that allow unauthenticated file read, file deletion, and SQL injection attacks, potentially leading to remote …

Hackers Can Weaponize ‘Summarize with AI’ Buttons to Inject Memory Prompts Into AI Recommendations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security threat has emerged targeting users of AI assistants through a technique called AI Recommendation Poisoning. Companies and threat actors embed hidden instructions in seemingly harmless “Summarize with …

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign targeting macOS users has emerged, deploying a dangerous stealer malware through an evolved version of the ClickFix attack technique. Named “Matryoshka” after the Russian nesting …

LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new version of LockBit ransomware has emerged, targeting multiple operating systems and threatening businesses worldwide. LockBit 5.0, released in September 2025, represents a major upgrade to one of …

New ZeroDayRAT Attacking Android and iOS For Real-Time Surveillance and Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ZeroDayRAT is a new mobile spyware platform sold openly through Telegram, with activity first observed on February 2, 2026. It targets Android (5–16) and iOS (up to 26), giving attackers …