Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term …

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in …

Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile, Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to …

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected …

ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual …

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Boston, MA, USA, September 8th, 2026, CyberNewswire Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation.  Reflectiz, …

Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, NY, United States, September 8th, 2026, CyberNewswire Mars Security, the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a …

Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Claude Mythos is the first model reported to complete a cyber kill chain without step-by-step human direction. The finding does not describe malware or a confirmed victim breach. It is …

Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft …

WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s WeChat account in seconds without the victim …