Critical FortiSIEM Vulnerability Lets Attackers Run Arbitrary Commands via TCP Packets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet disclosed a critical OS command injection vulnerability in FortiSIEM on January 13, 2026, warning users of a high-risk flaw that lets unauthenticated attackers execute arbitrary code. Tracked as CVE-2025-64155, …

Betterment Confirms that Hackers Gained Access to Internal Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A leading digital wealth management platform disclosed on January 9, 2026, that an unauthorized individual obtained access to its internal systems through a sophisticated social engineering attack. Enabling them to …

New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has identified a critical bug affecting Android devices where the volume buttons malfunction when the Select to Speak accessibility feature is enabled. The issue causes volume keys to adjust …

Spring CLI Tool Vulnerability Enables Command Execution on the Users Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A command injection vulnerability in the Spring CLI VSCode extension poses a security risk to developers still using the outdated tool. The flaw, tracked as CVE-2026-22718, enables attackers to execute …

Top 11 Best DNS Filtering Solutions – 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Before diving into DNS filtering solutions, it’s essential to understand the concept of DNS filtering and its significance in cybersecurity. In today’s digital landscape, cybersecurity has become a critical priority …

Microsoft Desktop Window Manager 0-Day Vulnerability Exploited in the wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft patched a critical zero-day information disclosure flaw in its Desktop Window Manager (DWM) on January 13, 2026, in the Patch Tuesday update after detecting active exploitation in the wild. …

Microsoft Patch Tuesday January 2026 – 114 Vulnerabilities Fixed Including 3 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s January 2026 updates fix 114 vulnerabilities, with several remote code execution bugs rated critical across Office applications and Windows services such as LSASS. This Patch Tuesday addresses critical remote …

FortiSandbox SSRF Vulnerability Allow Attacker to proxy Internal Traffic via Crafted HTTP Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet disclosed a Server-Side Request Forgery (SSRF) vulnerability in its FortiSandbox appliance on January 13, 2026, urging users to update amid risks of internal network proxied requests. Tracked as CVE-2025-67685 …