Microsoft MFA Down – 504 Gateway Timeout Errors Disrupting MFA Access for U.S. Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is currently investigating a significant service degradation affecting Multi-Factor Authentication (MFA) across its Microsoft 365 suite, with users in the North America region reporting widespread 504 gateway timeout errors …

New Phishing Framework Starkiller Proxies Real Login Pages to Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A highly sophisticated phishing framework named Starkiller has recently emerged, offering attackers an advanced method to steal credentials and bypass multi-factor authentication. Developed by a group known as Jinkusu, this …

North Korean Threat Actors Leverage Fake IT Worker Campaigns and Contagious Interview Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean nation-state threat actors have been running a two-part operation — posing as job recruiters while embedding fake workers inside real companies. Since at least 2022, these actors have …

PoC Exploit Released for Grandstream GXP1600 VoIP Phones RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Grandstream GXP1600 VoIP Phones RCE Vulnerability A critical zero-day vulnerability, tracked as CVE-2026-2329, is affecting Grandstream’s GXP1600 series VoIP desk phones. The issue is an unauthenticated stack-based buffer overflow that …

jsPDF Vulnerability Exposes Millions of Developers to Object Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

jsPDF Vulnerability Injection Attacks A newly disclosed security flaw in the popular jsPDF library has exposed millions of web developers to PDF Object Injection attacks, allowing remote attackers to embed arbitrary objects and …

CISA Warns of Multiple Roundcube Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has officially updated its Known Exploited Vulnerabilities (KEV) Catalog to include new security flaws affecting a popular webmail platform. On February 20, 2026, the agency added two critical vulnerabilities …

OWASP Smart Contract Top 10 2026 — Security Risks and Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OWASP Smart Contract Top 10 2026 The Open Web Application Security Project (OWASP) has published the Smart Contract Top 10: 2026, a forward-looking standard awareness document designed to arm Web3 …

Google Suspends OpenClaw Users from Antigravity AI After OAuth Token Abuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Suspends OpenClaw Users Google has suspended access to its Antigravity AI platform for numerous users of the open-source tool OpenClaw, sparking backlash over aggressive enforcement of terms of service …

DPRK Linked Operators Sustain Aggressive Crypto Targeting 12 Months After Bybit Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

February 21, 2026, marks one year since North Korea (DPRK)-linked operators stole approximately $1.46 billion in cryptoassets from Dubai-based exchange Bybit — the largest confirmed crypto theft in history. Rather …

Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. This operation focuses heavily on Asia, targeting local organizations with carefully localized …