GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab Patches Vulnerabilities A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions …

Windows Notepad Vulnerability Allows Attackers to Execute Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Notepad RCE Vulnerability Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on …

Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access. The flaw stems …

Microsoft Patch Tuesday February 2026 – 54 Vulnerabilities Fixed, Including 6 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Patch Tuesday February 2026 Microsoft released its February 2026 Patch Tuesday updates on February 10, addressing 54 vulnerabilities, including six zero-days across Windows, Office, Azure, and developer tools. The …

FortiSandbox XSS Vulnerability Let Attackers Run Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiSandbox XSS Vulnerability Fortinet has disclosed a high-severity cross-site scripting (XSS) vulnerability in its FortiSandbox platform, tracked as CVE-2025-52436 (FG-IR-25-093), that enables unauthenticated attackers to execute arbitrary commands on affected …

Threat Hunting Is Critical to SOC Maturity but Often Misses Real Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat Hunting Is Critical to SOC High-performing SOC teams are increasingly turning to sandbox-derived threat intelligence to make threat hunting repeatable and impactful. Tools like ANY.RUN’s TI Lookup enables faster …

FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiOS Authentication Bypass Vulnerability Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN …

APT36 Hacker Group Attacking Linux Systems with New Tools to Disturb Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

For more than a decade, Indian government and defense organizations have operated under a constant digital shadow. A tightly connected espionage ecosystem, primarily involving the Transparent Tribe (APT36) group and …

Threat Actors Weaponizes Bing Ads Attack Users with Azure Tech Support Scams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated tech support scam campaign has emerged, exploiting Bing search advertisements to redirect unsuspecting users to fraudulent pages hosted on Microsoft Azure Blob Storage. This operation has affected users …