News

Cyber Security News
cyberpress.org > project-zero-zero-click-exploit-pixel-9

Google Project Zero Reveals Sophisticated Zero-Click Exploit Chain Targeting Pixel 9

10+ hour ago   (365+ words) Project Zero, has disclosed a sophisticated zero-click exploit chain targeting the Pixel 9 smartphone, demonstrating that highly advanced attacks remain viable even against modern Android security defenses. The research, published in January 2026, showcases how threat actors could compromise devices through audio…...

Cyber Security News
cyberpress.org > uat-8837-hackers-open-source-tools-data-theft

UAT-8837 Hackers Target Organizations Using Open-Source Tools to Steal Sensitive Data

11+ hour, 53+ min ago   (486+ words) UAT-8837 Hackers Target Organizations Using Open-Source Tools to Steal Sensitive Data'Cyber Press UAT-8837 Hackers Target Organizations Using Open-Source Tools to Steal Sensitive Data Active since at least 2025, the threat actor demonstrates sophisticated tradecraft and likely possesses zero-day exploitation capabilities. Exploitation…...

Cyber Security News
cyberpress.org > aws-console-supply-chain-attack-github-hijackingcyber

New AWS Console Supply Chain Attack Sees Hackers Hijack AWS GitHub Repositories

13+ hour, 58+ min ago   (410+ words) Researcher has uncovered CodeBreach, a critical vulnerability that threatens the AWS Console supply chain by enabling the complete takeover of key AWS GitHub repositories. The flaw allowed attackers to compromise the AWS JavaScript SDK, a foundational library powering the AWS…...

Cyber Security News
cyberpress.org > hackers-abuse-legitimate-cloud-and-cdn

Hackers Abuse Legitimate Cloud and CDN Platforms to Host Phishing Kits

1+ day, 8+ hour ago   (218+ words) Cybersecurity researchers have identified a troubling trend in which sophisticated threat actors are leveraging legitimate cloud and content delivery network (CDN) infrastructure from major technology providers, including Microsoft Azure, Google Cloud, and AWS CloudFront, to host phishing kits while evading…...

Cyber Security News
cyberpress.org > microsoft-warns-of-windows-remote-assistance-security-bypass-vulnerability

Microsoft Warns of Windows Remote Assistance Security Bypass Vulnerability

1+ day, 9+ hour ago   (300+ words) Microsoft has disclosed a new security vulnerability in Windows Remote Assistance that could allow local attackers to bypass critical security features on affected systems. The vulnerability, tracked as CVE-2026-20824, was publicly disclosed on January 13, 2026, and has been assigned an "Important…...

Cyber Security News
cyberpress.org > critical-cal-com-flaw-2

Critical Cal.com Flaw Allows Authentication Bypass and Account Takeover

1+ day, 10+ hour ago   (229+ words) A newly disclosed flaw in Cal.com, the popular open-source scheduling platform, could have allowed attackers to hijack any user account simply by knowing the victim's email address, bypassing all authentication and even multi-factor protections. Subsequent requests authenticated with this…...

Cyber Security News
cyberpress.org > palo-alto-networks-firewall-flaw

Palo Alto Networks Firewall Flaw Enables Denial-of-Service Attacks

1+ day, 12+ hour ago   (355+ words) The vulnerability carries a CVSS v4.0 base score of 7.7, classified as HIGH severity, with an elevated base score of 8.7 when environmental factors are considered. Disclosed on January 14, 2026, the security issue stems from improper validation of unusual or exceptional conditions within the…...

Cyber Security News
cyberpress.org > chinese-threat-actors-operated

Chinese Threat Actors Operated 18,000 Active C2 Servers Across Global Hosting Providers

1+ day, 12+ hour ago   (372+ words) Threat actors linked to Chinese hosting infrastructure have established a large network of more than 18,000 active command-and-control servers across 48 hosting providers in recent months. This widespread abuse highlights a serious issue: malicious infrastructure can hide within trusted networks and cloud…...

Cyber Security News
cyberpress.org > microsoft-sql-server-flaw

Microsoft SQL Server Flaw Enables Network-Based Privilege Escalation

2+ day, 6+ hour ago   (401+ words) Microsoft has disclosed a critical elevation-of-privilege vulnerability in SQL Server that allows attackers with high privileges to escalate their access over a network without requiring user interaction. The vulnerability, tracked as CVE-2026-20803, was released on January 13, 2026, and stems from missing…...

Cyber Security News
cyberpress.org > aurainspector-open-source-salesforce-aura-security-tool

AuraInspector: An Open-Source Tool for Auditing Salesforce Aura Misconfigurations

2+ day, 8+ hour ago   (333+ words) The tool focuses on finding exposed data paths that could allow unauthorized users to access sensitive records, such as financial, identity, or health information, from an external perspective. Salesforce Aura is the framework behind Salesforce's Lightning Experience UI and Experience…...