Splunk Enterprise for Windows Vulnerability Let Attackers Hijack DLLs and Gain SYSTEM Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has disclosed a high-severity vulnerability in Splunk Enterprise for Windows that allows a low-privileged local user to escalate their privileges to SYSTEM level through a DLL search-order hijacking attack. …

Adidas Investigates Alleged Data Breach – 815,000 Records of Customer Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adidas has confirmed it is actively investigating a potential data breach involving one of its independent third-party partners after a threat actor operating under the alias “LAPSUS-GROUP” posted claims on …

OpenClaw’s Top Skill is a Malware that Stole SSH Keys, and Opened Reverse Shells in 1,184 Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenClaw’s Top Skill Malware The most downloaded AI agent skill on OpenClaw’s ClawHub marketplace was functional malware, not a productivity tool. OpenClaw, an open-source AI agent platform, operates a public …

Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of a distinct vulnerability disclosure ecosystem within China has introduced a complex layer to the global threat landscape. Unlike the centralized CVE system used internationally, China maintains two …

AI Under Control: Link11 Launches AI Management Dashboard for Clean Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Frankfurt am Main, Germany, February 19th, 2026, CyberNewswire Link11 launches its new “AI Management Dashboard”, closing a critical gap in how companies manage AI traffic. Artificial intelligence is fundamentally changing …

PromptSpy – First Known Android AI Malware Uses Google’s Gemini for Decision-making

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first known Android malware family to weaponize a generative AI model, specifically Google’s Gemini, as part of its active execution flow. Discovered in February 2026, the malware represents a …

Threat Actors Using Fake Google Forms Site to Harvest Google Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing campaign is targeting job seekers through fake Google Forms websites designed to steal login credentials. The campaign uses sophisticated domain impersonation techniques to trick victims into revealing …

CISA Warns of Honeywell CCTV Products Vulnerability Leads to Account Takeovers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical advisory warning regarding a severe vulnerability affecting Honeywell CCTV products, published on February 17, 2026, under advisory ICSA-26-048-04. The alert details a high-severity security flaw that could allow …

Hackers Leveraging nslookup.exe to Stage Payloads via DNS Using Clickfix Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Clickfix Attack Using nslookup A sophisticated evolution of the ClickFix social engineering campaign, in which threat actors are now abusing the legitimate Windows utility nslookup.exe to deploy malicious payloads via …

XWorm Malware Delivered via Fake Financial Receipts Targeting Windows Systems to Steal Logins and Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign is actively targeting Brazilian and Latin American (LATAM) businesses using fake bank receipts to deliver XWorm v5.6, a commodity remote access trojan (RAT) capable of …