Skip to content

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

January 2026

CVE-2026-21227: Azure Logic Apps Flaw Opens Door to Silent Privilege Escalation

  • Uncategorized
AegironJanuary 25, 2026January 25, 20268 mins0
CVE-2026-21227 — Azure Logic Apps Path Traversal → Elevation of Privilege CVE ID: CVE-2026-21227Affected Service: Azure Logic…
continue reading..

CVE-2026-24306 : Critical Azure Front Door Flaw Opens Door to Silent Cloud Privilege Escalation

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 202610 mins0
Azure Front Door – Privilege Escalation via Control-Plane Abuse CVE ID: CVE-2026-24306Affected Service: Azure Front DoorVulnerability Type:…
continue reading..

CVE-2025-54816: Critical WebSocket Authentication Flaw Exposes EV Charging Control Systems to Remote Takeover

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 20268 mins0
CVE-2025-54816 — Missing Authentication on WebSocket Endpoint CVE ID: CVE-2025-54816Vulnerability Name: WebSocket Endpoint Missing AuthenticationCategory: Authentication Bypass…
continue reading..

CVE-2026-21264: Critical Flaw in Microsoft Account Login Pages Enables Spoofed Sign-In Attacks and Account Takeover Risk

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 20269 mins0
CVE-2026-21264 — Microsoft Account XSS / Spoofing Vulnerability CVE Identifier: CVE-2026-21264CVSS v3.1 Score: 9.3 (Critical)Affected Component: Microsoft…
continue reading..

CVE-2026-24304: Critical Azure Resource Manager Flaw Opens Door to Cloud Tenant Takeover

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 20268 mins0
CVE-2026-24304 – Azure Resource Manager Privilege Escalation CVE ID: CVE-2026-24304Component: Azure Resource Manager (ARM)Vulnerability Type: Improper Access…
continue reading..

CVE-2026-0775: npm CLI Bug Turns Developer Machines Into Privilege Escalation Targets

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 202610 mins0
CVE-2026-0775 — npm CLI Local Privilege Escalation CVE ID: CVE-2026-0775Affected component: npm CLIVulnerability class: Local Privilege Escalation…
continue reading..

Gitea Under Threat: Critical Authorization Flaws Lead to Destructive and Org-Wide Attacks

  • Vulnerabilities
AegironJanuary 25, 2026January 25, 20267 mins0
Product Overview Product: GiteaCategory: Self-hosted Git repository management platformTypical Users: Enterprises, DevOps teams, open-source maintainersCore Risk Area:…
continue reading..

Hackers Exploit ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in Sophisticated Phishing Campaign

  • CyberSecurity News
CyberDefenderJanuary 25, 2026January 25, 20264 mins0
Cybercriminals are exploiting a visual typo trick known in cybersecurity as typosquatting or a homoglyph attack —…
continue reading..

North Korea–Linked KONNI Group Targets Developers With AI-Generated Malware, Researchers Warn

  • CyberSecurity News
CyberDefenderJanuary 24, 2026January 24, 202614 mins0
In a significant escalation of cybercrime tactics, the North Korea–linked threat actor KONNI has shifted its sights…
continue reading..

CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog, Urges Immediate Patching

  • CyberSecurity News
CyberDefenderJanuary 24, 2026January 24, 20267 mins0
CVE-2024-37079, a critical vulnerability affecting VMware vCenter Server, has been added to the Known Exploited Vulnerabilities (KEV)…
continue reading..
  • 1
  • …
  • 15
  • 16
  • 17
  • 18
  • 19
  • …
  • 75

Recent Posts

  • Ransomware Group ‘Gentlemen’ Industrializes EDR Evasion with Kernel-Le…
    Jun 22, 2026
  • SmartApeSG Compromises Okendo Reviews Widget, Exposing Thousands of E-…
    Jun 22, 2026
  • Cybercriminals Exploit Fake Microsoft Teams Transcripts to Deploy Pers…
    Jun 22, 2026
  • Thousands Targeted, Hundreds Compromised: Inside the FortiBleed Creden…
    Jun 22, 2026
  • Novel GhoLoader malware campaign detected, using unique ’10 mous…
    Jun 22, 2026
  • INC Ransomware Emerges as a Major Global Cyber Threat, Rapidly Expandi…
    Jun 19, 2026
  • Dropping Elephant Deploys Advanced Fileless Malware, Neutralizing AMSI…
    Jun 19, 2026
  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Compromises Universi…
    Jun 19, 2026
  • Cybercriminals Weaponize Wallpaper Engine to Hijack Steam Accounts in …
    Jun 19, 2026
  • AI-Powered ClickFix Campaign Targets Brazilian Banks, Deploys SmartRAT…
    Jun 19, 2026

Popular Posts

No posts found.

Find Me On

©Cyber Security Priority 1(P1) News 2026. All Rights Reserved.
  • Contact
  • Privacy Policy
  • Terms of Service