Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran’s cyber operations took a sharp turn in early 2026, with state-linked threat actors quietly embedding themselves inside US and Canadian networks while also targeting internet-connected surveillance cameras across the …

Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape entered a new phase in 2025. Once a highly reliable criminal business model built on encrypting victim files and collecting ransom payments, it is now under …

Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated supply chain attack struck the developer community on March 16, 2026, when a threat actor known as Glassworm backdoored two widely used React Native npm packages, turning them …

AWS Bedrock AgentCore Sandbox Bypass Allows Covert C2 Channels and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw in AWS Bedrock AgentCore Code Interpreter’s “Sandbox” network mode, a feature advertised by AWS as providing complete network isolation that allows outbound DNS queries, enabling threat …

To Beat Alert Overload, Stop Wasting Time on False Positives 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

To Beat Alert Overload, Stop Wasting Time on False Positives  At first glance, false positives in cybersecurity seem almost comforting.  An alert fires. A SOC analyst investigates. It turns out to be nothing malicious. Case closed. Systems are safe, detection works, and the organization moves on.  In theory, …

Attackers Use SEO Poisoning and Signed Trojans to Steal VPN Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat actor known as Storm-2561 has been running a credential theft campaign since May 2025, manipulating search engine rankings to push fake VPN software toward enterprise users. …

Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kubernetes CSI Driver NFS Vulnerability A path traversal vulnerability has been identified in the Kubernetes Container Storage Interface (CSI) Driver for NFS, potentially allowing attackers to delete or modify unintended …

New Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues Microsoft has rolled out an out-of-band update for Windows 11 users to address a frustrating interface bug affecting Bluetooth device visibility. …

Angular XSS Vulnerability Exposes Thousands of web Applications to XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Angular XSS Vulnerability Exposes web Applications A high-severity Cross-Site Scripting (XSS) vulnerability has been discovered in the widely used Angular framework. Tracked as CVE-2026-32635 and categorized under CWE-79, this flaw …

Orchid Security Recognized by Gartner® as a Representative Vendor of Guardian Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, United States, March 17th, 2026, CyberNewswire Unleash AI adoption securely: discover, attribute, and govern AI agents throughout the enterprise Orchid Security, the company bringing clarity and control to …