Researchers Detailed r1z Initial Access Broker OPSEC Failures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. authorities have pulled back the curtain on “r1z,” an initial access broker who quietly sold gateways into corporate networks around the world. Operating across popular cybercrime forums, he offered …

Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities – Pwn2Own Automotive 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Day One of Pwn2Own Automotive 2026, which delivered $516,500 USD for 37 zero-days, the event has now accumulated $955,750 USD across 66 unique vulnerabilities, demonstrating the automotive sector’s substantial attack …

Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in SmarterTools SmarterMail is actively being exploited in the wild by attackers, according to security researchers at watchTowr Labs. The vulnerability, tracked as WT-2026-0001, allows …

New ClickFix Campaign Hijacks Facebook Sessions Using Fake Verification Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers have launched a widespread campaign called ClickFix that steals Facebook account credentials by tricking users into handing over their session tokens. Rather than using complex malware or software exploits, …

Critical Vivotek Vulnerability Allows Remote Users to Inject Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code injection vulnerability in Vivotek legacy firmware that enables unauthenticated attackers to execute arbitrary commands with root privileges. The vulnerability, tracked as CVE-2026-22755, affects dozens of camera …

FortiGate Firewalls Hacked in Automated Attacks to Steal Configurations Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new cluster of automated malicious activity targeting FortiGate firewall devices. Beginning January 15, 2026, threat actors have been observed executing unauthorized configuration changes, establishing persistence through generic accounts, and …

BIND 9 Vulnerability Allow Attackers to Crash Server by Sending Malicious Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been disclosed in BIND 9, the widely used DNS server software responsible for domain name resolution across millions of internet services. The vulnerability, tracked as CVE-2025-13878, …

New Multi-Stage Windows Malware Disables Microsoft Defender Before Dropping Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a sophisticated multi-stage malware campaign targeting Windows systems through social engineering and weaponized cloud services. The attack employs business-themed documents as deceptive entry points, luring users …

Critical Vulnerability in Binary-Parser Library for Node.js Allows Malicious Code injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical code-injection vulnerability has been identified in the Node.js binary-parser library, affecting all versions before 2.3.0. The flaw allows attackers to execute arbitrary JavaScript code if untrusted input is …

New AI-Android Malware that Auto Clicks Ads from the Infected Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Android malware campaign has emerged, targeting users through mobile games and pirated streaming app modifications. The threat, known as Android.Phantom, employs machine learning technology to perform automated ad-click …