Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released emergency out-of-band security updates on January 26, 2026, to address CVE-2026-21509, a zero-day security feature bypass vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated …

New Lawsuit Claims that Meta Can Read All the WhatsApp Users Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new class-action lawsuit accuses Meta Platforms of misleading billions of WhatsApp users by claiming their messages are protected by unbreakable end-to-end encryption. Filed in the San Francisco federal court, …

Best VPN Services of 2026: Fast, Secure & Affordable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s digital world, online privacy and security have never been more important. With cybercrime on the rise and government surveillance becoming more common, protecting your personal information online is …

Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clawdbot, the surging open-source AI agent gateway, faces escalating security concerns, with 900+ unauthenticated instances exposed online and multiple code flaws that enable credential theft and remote code execution. Clawdbot …

800K+ GNU InetUtils telnetd Instances Exposed to RCE Attacks – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the telnetd component of GNU Inetutils has exposed approximately 800,000 internet-accessible Telnet instances to unauthenticated remote code execution (RCE). Tracked as CVE-2026-24061 with a …

Curl to End Bug Bounty Following Low-Quality AI-Generated Vulnerability Reports

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The curl project ended its bug bounty program in January 2026 because it received too many low-quality and useless bug reports. The decision reflects growing frustration within the open-source security …

New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Browser attacks have become far more dangerous and organized than before. A new threat called Stanley, discovered in January 2026, shows just how serious the problem has become. This malware-as-a-service …

Lazarus Hackers Actively Attacking European Drone Manufacturing Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus, a sophisticated North Korean-aligned hacking group also known as HIDDEN COBRA, has launched a new wave of targeted attacks against European drone manufacturers and defense contractors. The campaign, tracked …