Aggregator
Google confirms Android bug causing volume key issues
When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering
When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering
Russian Eco-Fuel Company Palevo Allegedly Breached with 2021 User Registration Data Leaked
Microsoft Patch Tuesday January 2026 – 114 Vulnerabilities Fixed Including 3 Zero-days
Microsoft’s January 2026 updates fix 114 vulnerabilities, with several remote code execution bugs rated critical across Office applications and Windows services such as LSASS. This Patch Tuesday addresses critical remote code execution flaws and numerous elevation of privilege issues that could enable attackers to compromise systems. Vulnerability Type Count Remote Code Execution 22 Denial of […]
The post Microsoft Patch Tuesday January 2026 – 114 Vulnerabilities Fixed Including 3 Zero-days appeared first on Cyber Security News.
AI Supply Chain Risk: Will CIOs Be Held Accountable?
IT organizations have built processes for reducing vendor risk, but in the AI era, that operating model is being dismantled. Modern AI environments are built on dynamic external foundational models, countless APIs, open-source components and continuous data pipelines that pose risks.
One Simple Trick to Knock Out the Wi-Fi Network
A flaw in Broadcom chipsets commonly used in wireless routers allows attackers to repeatedly knock offline the 5 gigahertz band, no matter how strong the security settings, say researchers.
FortiSandbox SSRF Vulnerability Allow Attacker to proxy Internal Traffic via Crafted HTTP Requests
Fortinet disclosed a Server-Side Request Forgery (SSRF) vulnerability in its FortiSandbox appliance on January 13, 2026, urging users to update amid risks of internal network proxied requests. Tracked as CVE-2025-67685 (FG-IR-25-783), the flaw resides in the GUI component and stems from CWE-918, enabling authenticated attackers to craft HTTP requests that proxy traffic to internal plaintext […]
The post FortiSandbox SSRF Vulnerability Allow Attacker to proxy Internal Traffic via Crafted HTTP Requests appeared first on Cyber Security News.
CVE-2025-68622 | Espressif esp-usb up to 2.3.x USB Video Class Device stack-based overflow (GHSA-g65h-9ggq-9827 / EUVD-2025-206283)
CVE-2025-63314 | DDSN Acora CMS 10.7.1 Password Reset Token password recovery (EUVD-2026-1916)
CVE-2025-68656 | Espressif esp-usb up to 1.0.x usb_class_request_get_descriptor use after free (EUVD-2025-206282)
CVE-2025-68657 | Espressif esp-usb up to 1.0.x USB Event Callback hid_host_device_close double free (EUVD-2025-206281)
Shadow#Reactor Uses Text Files to Deliver Remcos RAT
科技云报到:RPA+Agent,为什么可以1+1>2?
CVE-2026-22771 | Envoy Proxy up to 1.5.6/1.6.1 EnvoyExtensionPolicy Lua Script code injection (GHSA-xrwg-mqj6-6m22 / EUVD-2026-2007)
200 млрд солнц умерли от голода: ядро лишило галактику «еды», превратив холодный газ в бесполезный кипяток
Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines
Node.js issued critical security updates across its active release lines on January 13, 2026, patching vulnerabilities that could lead to memory leaks, denial-of-service attacks, and permission bypasses. These releases address three high-severity flaws, among others, urging immediate upgrades for affected systems. High Severity Vulnerabilities High-severity issues dominate this release, with CVE-2025-55131 exposing uninitialized memory in […]
The post Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines appeared first on Cyber Security News.