New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user …

AWS Cost Explorer Bug Shows Trillion-Dollar Billing Estimates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 AWS customers worldwide were startled after the AWS Billing and Cost Management Console and Cost Explorer began displaying extraordinarily high projected cloud costs. Some organizations reported estimated monthly bills reaching trillions of dollars, triggering budget alerts and …

New ClickLock macOS Stealer Kills Every App to Force Password Entry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 New ClickLock macOS Stealer Kills Every App to Force Password Entry A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, …

CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems …

Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 …

Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive …

GPT-5.6 Codex is Reportedly Deleting Files From Home Directories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 OpenAI is currently investigating a small number of reports indicating that the GPT-5.6 Codex unintentionally deleted files from users’ home directories. These incidents reportedly occurred when Codex was granted full filesystem access without the necessary sandbox protections …

CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 CISA has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers are actively exploiting the flaws in real-world attacks. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated attackers to …

Two Hackers Jailed for Hacking 148 TfL Systems, Forcing Password Reset for 27,000 staffs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 Two young members of the Scattered Spider cybercrime group have been jailed for a 2024 attack that knocked out 148 Transport for London (TfL) systems, forced all 27,000 staff to reset passwords in person, and cost the …

7-Zip Vulnerability Exposes Millions of Users to Remote Code Execution Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems. Tracked as CVE-2026-14266, the flaw stems from improper handling of …