CISA Adds TrueConf Vulnerability to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting TrueConf software to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-3502, this security flaw is …

2,000+ FortiClient EMS Instances Exposed Online Amid Active RCE Vulnerability Exploits in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has issued an urgent warning to FortiClient Enterprise Management Server (EMS) administrators after identifying over 2,000 publicly accessible instances globally, two of which are now confirmed to …

Google DeepMind Researchers Warn Hackers Can Hijack AI Agents Through Malicious Web Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Google DeepMind have published a comprehensive study revealing that autonomous AI agents browsing the web are deeply vulnerable to a new class of attacks called “AI Agent Traps,” …

Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has issued an emergency hotfix after security researchers disclosed a critical zero-day vulnerability in FortiClient EMS that is already being actively exploited by threat actors. Tracked as CVE-2026-35616 and …

New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous attack chain in Progress ShareFile that can allow attackers to take over exposed on-premises servers without first logging in. The issues affect customer-managed ShareFile Storage Zones Controller 5.x …

Hackers Weaponize Claude Code Leak to Spread Vidar and GhostSocks Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is on high alert following a massive source code leak from Anthropic. On March 31, 2026, the company accidentally exposed the complete source code for Claude Code, …

Top Node.js Maintainers Targeted in Sophisticated Social Engineering Scheme

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly coordinated social engineering campaign is actively targeting top open-source developers in the Node.js and npm ecosystem. Following the recent compromise of the popular package Axios, which sees over …

Top 10 Best User Access Management Tools in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Best User Access Management Tools User Access Management tools centralize control over user permissions and access, providing a unified platform to enforce consistent security policies across diverse systems and applications. …