Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiClient SQL Injection vulnerability A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS). Tracked as CVE-2026-21643, this severe flaw carries a CVSS score of 9.1. It allows …

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Local Privilege Escalation (LPE) vulnerability in default installations of Ubuntu Desktop 24.04 and later allows an unprivileged local attacker to gain full root access. Tracked as CVE-2026-3888, uncovered by …

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Detection and Response Team details a sophisticated voice phishing (vishing) campaign that successfully compromised a corporate environment in November 2025. Unlike conventional intrusions that rely on software exploits, this …

Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iran’s cyber operations took a sharp turn in early 2026, with state-linked threat actors quietly embedding themselves inside US and Canadian networks while also targeting internet-connected surveillance cameras across the …

Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ransomware threat landscape entered a new phase in 2025. Once a highly reliable criminal business model built on encrypting victim files and collecting ransom payments, it is now under …

Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A coordinated supply chain attack struck the developer community on March 16, 2026, when a threat actor known as Glassworm backdoored two widely used React Native npm packages, turning them …

AWS Bedrock AgentCore Sandbox Bypass Allows Covert C2 Channels and Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security flaw in AWS Bedrock AgentCore Code Interpreter’s “Sandbox” network mode, a feature advertised by AWS as providing complete network isolation that allows outbound DNS queries, enabling threat …

To Beat Alert Overload, Stop Wasting Time on False Positives 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

To Beat Alert Overload, Stop Wasting Time on False Positives  At first glance, false positives in cybersecurity seem almost comforting.  An alert fires. A SOC analyst investigates. It turns out to be nothing malicious. Case closed. Systems are safe, detection works, and the organization moves on.  In theory, …

Attackers Use SEO Poisoning and Signed Trojans to Steal VPN Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat actor known as Storm-2561 has been running a credential theft campaign since May 2025, manipulating search engine rankings to push fake VPN software toward enterprise users. …

Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kubernetes CSI Driver NFS Vulnerability A path traversal vulnerability has been identified in the Kubernetes Container Storage Interface (CSI) Driver for NFS, potentially allowing attackers to delete or modify unintended …