Pro-Iran Hacktivists Use Telegram-Coordinated DDoS and Hack-and-Leak Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Pro-Iran hacktivist networks are turning Telegram channels into hubs for cyber retaliation. Their campaigns combine website-disrupting DDoS floods with hack-and-leak claims, using public posts to recruit supporters, circulate target lists, and magnify disruption. The activity has created …

New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT hash and NTLM password hashes for every account in the …

CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS versions 12.4(12) and 12.4(4). This vulnerability was added to CISA’s …

UK and Allies Warn of Russian Hackers Actively Hacking Organizations’ Routers Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The UK, joined by international cybersecurity partners, has issued an urgent warning about Russian state-backed hackers targeting poorly secured routers and network devices worldwide. The alert focuses on Center 16, a cyber unit linked to Russia’s Federal …

SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory Corruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 SAP has released its July 2026 Security Patch Day updates, addressing a critical memory corruption vulnerability in the SAP NetWeaver Application Server ABAP. The most severe issue, tracked as CVE-2026-44747, has a CVSS score of 9.9 and …

Greenhat Announces Successful Delegation at Web Summit Vancouver 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international innovation leaders during one …

150+ npm Packages Promises Wi-Fi Bypass Students Using Their Systems for DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Nearly 150 npm packages posing as school Wi-Fi bypass tools were used to turn visiting browsers into potential DDoS engines. The campaign presented itself as harmless tutoring-branded web proxies, giving students a way to reach blocked websites …

Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is retiring phishable SMS and voice-based multifactor authentication in Microsoft Entra ID, replacing them with passkeys as the default sign-in method starting September 1, 2026. The move responds to a surge in AI-enabled phishing campaigns that Microsoft Threat Intelligence …

US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has imposed sanctions on First VPN Service (1VPNS), a VPN provider accused of supplying infrastructure to ransomware groups targeting American organizations. The action also targets …

Critical ServiceNow Vulnerability Allows Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ServiceNow has disclosed and fixed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to execute code within affected ServiceNow environments. The flaw, tracked as CVE-2026-6875, is described as a sandbox escape vulnerability and affects both …