Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An unprecedented surge in exploitation attempts targeting CVE-2026-1281, a critical vulnerability in Ivanti Endpoint Manager Mobile (EPMM). On February 9, 2026, Shadowserver scans revealed over 28,300 unique source IP addresses …

Prometei Botnet Attacking Windows Server to Gain Remote Access and Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Prometei Botnet Attacking Windows Server A sophisticated attack is targeting Windows Server systems using Prometei, a Russian-linked botnet that has been active since 2016. This multi-functional malware combines cryptocurrency mining, …

Critical SandboxJS Vulnerability Allows Remote Host Takeover – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SandboxJS Vulnerability PoC Released A severe sandbox escape vulnerability has been discovered in the JavaScript library, enabling attackers to execute arbitrary code on host systems. The flaw, tracked as CVE-2026-25881 …

Legacy IRC Botnet Campaign Uses Automated SSH Compromise Pipeline to Enroll Linux Hosts at Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SSHStalker is a newly discovered Linux botnet that brings back Internet Relay Chat (IRC) control while using automation to compromise servers over SSH. It mainly succeeds by guessing weak or …

GitGuardian Raises $50M Series C to Address Non-Human Identities Crisis and AI Agent Security Gap

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, NY, February 11th, 2026, CyberNewswire Insight Partners leads round, alongside Quadrille Capital, to accelerate expansion across Americas, EMEA, and strategic verticals GitGuardian, a leading secrets and Non-Human Identity …

MSHTML Framework 0-Day Vulnerability Let Attackers Security Feature over Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MSHTML Framework 0-Day Vulnerability Microsoft has released an urgent security patch for a critical zero-day vulnerability (CVE-2026-21513) affecting the MSHTML Framework, which was actively exploited in the wild before a …

Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Office Word 0-day Vulnerability A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections. This flaw …

Cephalus Ransomware Emerges as Go-Based Double-Extortion Threat Targeting Exposed RDP

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cephalus has surfaced as a Go-built ransomware strain linked to victim activity as early as June 2025, with wider public reporting appearing in August. It focuses on Windows networks and …

Microsoft Investigates Teams Assignment Errors After Failed Service Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Investigates Teams Assignment Errors Microsoft Teams faces widespread disruptions in assignment management, prompting an urgent investigation by the company. Users of Microsoft Teams are encountering error messages when trying …