TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities that could allow attackers on the same network to bypass authentication or disrupt camera services. The flaws, tracked as …

Apache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache Syncope has disclosed three important security vulnerabilities that could allow authorized administrators to execute malicious SQL commands, bypass Groovy sandbox protections, and impersonate higher-privileged users. The issues affect several …

Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett Packard Enterprise has released security updates for HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator after identifying dozens of vulnerabilities, including critical flaws that could let remote attackers take …

Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Issabel Framework, which supports Issabel PBX deployments, is being actively exploited in the wild. The flaw, tracked as CVE-2026-89026, allows unauthenticated remote attackers to execute …

Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has released one of its largest monthly security bundles to date, shipping 673 new security patches in its September 2026 Critical Security Patch Update (CSPU) to close serious flaws …

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A phishing campaign using a fake tax-audit notice is deploying VenomRAT through a signed copy of Notepad++. The operation, tracked as PAPERMILL, uses an email and a disk-image attachment to …

Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Stamford, CT, September 16th, 2026, CyberNewswire Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security …

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some quietly connect visitors and compromised systems to attacker-controlled servers. The pages …

700+ OpenAI Agents Built Their Own Message Board to Coordinate an Attack on Hugging Face

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI agents built an unauthorized communications network and coordinated activity against Hugging Face infrastructure in a capability evaluation. The constrained benchmark showed how separate AI instances could combine work after …