Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE). The patches resolve issues ranging from high-severity authentication flaws …

LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security alert regarding an active phishing campaign that commenced on January 19, 2026. The malicious actors are impersonating LastPass support staff and sending fraudulent emails claiming urgent vault …

AI Phishing Is Your Company’s Biggest Security Risk in 2026: Here’s How to Stop It 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing used to be easy to spot. Bad grammar, strange links, obvious scams. That version is gone.  In 2026, phishing is polished, well-written, and often smarter than it has any right …

NVIDIA NSIGHT Graphics for Linux Vulnerability Allows Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent security update addressing a critical vulnerability in NSIGHT Graphics for Linux that could allow attackers to execute arbitrary code on affected systems. The flaw, tracked as CVE-2025-33206, has …

Threat Actors Hiding stealthy PURELOGS Payload Within a Weaponized PNG File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered attack campaign has exposed a sophisticated delivery method for the PURELOGS infostealer, a commodity malware sold as a service on underground forums. Threat actors are using weaponized …

Oracle Critical Security Patch – 337 Vulnerabilities Patched Across Product Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A January 2026 Critical Patch Update addressing 337 new security vulnerabilities spanning multiple product families, marking a comprehensive security initiative to mitigate widespread risk across enterprise systems. The patch encompasses …

Multiple 0-day Vulnerabilities in Anthropic Git MCP Server Enables Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three zero-day vulnerabilities in mcp-server-git, the reference implementation of Git integration for the Model Context Protocol (MCP). The flaws stem from insufficient input validation and argument sanitization in core Git …

Beware of Weaponized Shipping Documents that Deliver Remcos RAT with a Wide Range of Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging a dangerous new campaign that weaponizes ordinary-looking shipping documents to distribute Remcos, a powerful remote access trojan. This phishing scheme uses fake shipping emails as the …

Hackers Extensively Abuses Visual Studio Code to Execute Malicious Payloads on Victim System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors linked to North Korea have continued to expand their attack capabilities by weaponizing Microsoft Visual Studio Code, one of the world’s most popular code editors. The Contagious Interview …

Microsoft Teams External Domain Anomalies Allow Defenders to Detect Attackers at Earliest

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is rolling out a new security feature called the External Domains Anomalies Report for Teams, designed to help IT administrators identify and respond to suspicious external communications before they …