Category: cyber-security-news

  • Hackers Exploiting Microsoft WSUS Vulnerability In The Wild – 2800 Instances Exposed Online

    Hackers Exploiting Microsoft WSUS Vulnerability In The Wild – 2800 Instances Exposed Online Hackers are actively exploiting a critical flaw in Microsoft’s Windows Server Update Services (WSUS), with security researchers reporting widespread attempts in the wild. The vulnerability, tracked as CVE-2025-59287, allows remote code execution on unpatched WSUS servers, potentially granting attackers full control over…

  • New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver

    New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver A new tool called EDR-Redir has emerged, allowing attackers to redirect or isolate the executable folders of popular Endpoint Detection and Response (EDR) solutions. Demonstrated by cybersecurity researcher TwoSevenOneT, the technique leverages Windows’ Bind Filter driver (bindflt.sys) and Cloud Filter driver (cldflt.sys) to…

  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control

    Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control A sophisticated backdoor named Android.Backdoor.Baohuo.1.origin has been discovered in maliciously modified versions of Telegram X messenger, granting attackers complete control over victims’ accounts while operating undetected. The malware infiltrates devices through deceptive in-app advertisements and third-party app stores, masquerading as legitimate dating…

  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments

    LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments The notorious LockBit ransomware operation has resurfaced with a vengeance after months of dormancy following Operation Cronos takedown efforts in early 2024. Despite law enforcement disruptions and infrastructure seizures, the group’s administrator, LockBitSupp, has successfully rebuilt the operation and launched LockBit 5.0, internally codenamed “ChuongDong.” This…

  • 706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released

    706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released A high-severity vulnerability in BIND 9 resolvers has been disclosed, potentially allowing attackers to poison caches and redirect internet traffic to malicious sites. Tracked as CVE-2025-40778, the flaw affects over 706,000 exposed instances worldwide, as identified by internet scanning firm Censys.…

  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials

    Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials Cybercriminals have adopted a sophisticated social engineering strategy that exploits the trust inherent in job hunting, according to a recent security advisory. A financially motivated threat cluster operating from Vietnam has been targeting digital advertising and marketing professionals through fake…

  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program

    Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program Southeast Asia’s online gambling ecosystem has become a breeding ground for sophisticated cyber threats, with criminal networks leveraging seemingly legitimate platforms to distribute malicious software to millions of unsuspecting users. A recently uncovered operation demonstrates how threat actors exploit the region’s thriving…

  • New Caminho Malware Loader Uses LSB Steganography and to Hide .NET Payloads Within Image Files

    New Caminho Malware Loader Uses LSB Steganography and to Hide .NET Payloads Within Image Files A sophisticated malware operation has emerged from Brazil, leveraging advanced steganographic techniques to conceal malicious payloads within seemingly harmless image files. The Caminho loader, active since at least March 2025, represents a growing threat to organizations across South America, Africa,…

  • Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks

    Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks BitLocker keys without PIN protection, where attackers could exploit stolen laptops, researchers now delve into PIN-secured setups, targeting insider threats seeking SYSTEM-level access. This technique involves intercepting TPM communications via SPI bus analysis, revealing how even PIN-hardened BitLocker can yield to physical…

  • New Text Message Based Phishing Attack from China Targeting Users Around the Globe

    New Text Message Based Phishing Attack from China Targeting Users Around the Globe A sophisticated text message phishing campaign originating from China has emerged as one of the most extensive cybersecurity threats targeting users worldwide. The operation, attributed to a threat collective known as the Smishing Triad, represents a massive escalation in SMS-based fraud, impersonating…

  • New Malware Attack Using Variable Functions and Cookies to Evade and Hide Their Malicious Scripts

    New Malware Attack Using Variable Functions and Cookies to Evade and Hide Their Malicious Scripts A sophisticated malware campaign targeting WordPress sites has emerged, utilizing PHP variable functions and cookie-based obfuscation to evade traditional security detection mechanisms. The attack represents an evolution in obfuscation techniques, where threat actors fragment malicious code across multiple HTTP cookies…

  • CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild

    CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations worldwide about active exploitation of a critical remote code execution (RCE) vulnerability in Microsoft’s Windows Server Update Services (WSUS). Tracked as CVE-2025-59287, the flaw carries a CVSS score of…

  • New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient

    New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent of detected cases. In a notable shift from traditional deployment methods, threat actors are now…

  • Toys “R” Us Canada Confirms Data Breach – Customers Personal Data Stolen

    Toys “R” Us Canada Confirms Data Breach – Customers Personal Data Stolen Toys “R” Us Canada has alerted customers to a significant data breach that potentially exposed their personal information, marking another blow to consumer trust in retail data security. In emails dispatched to affected individuals this morning, the popular toy retailer revealed that unauthorized…

  • Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

    Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing unauthorized attackers to execute…

  • Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories

    Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations’ critical code repositories and sensitive data. This emerging threat exploits misconfigured storage access controls to establish persistence and exfiltrate valuable intellectual property. The…

  • HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

    HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version 1.2.50.9581 of the agent, pushed silently to HP’s Next Gen AI systems like the EliteBook X Flip G1i, deleted…

  • DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users

    DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users The Department of Homeland Security (DHS) has issued the first known federal search warrant compelling OpenAI to disclose user data tied to ChatGPT prompts. The warrant, unsealed last week in Maine and reviewed by cybersecurity outlets, stems from a year-long probe into a…

  • Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial of Service Attacks

    Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial of Service Attacks The Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9 on October 22, 2025, potentially allowing remote attackers to conduct cache poisoning attacks or cause denial-of-service (DoS) conditions on affected DNS resolvers. These flaws, tracked as CVE-2025-8677, CVE-2025-40778, and CVE-2025-40780,…

  • Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox

    Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox Oracle has disclosed multiple critical vulnerabilities in its Oracle VM VirtualBox virtualization software, potentially allowing attackers to achieve complete control over the VirtualBox environment. These flaws, detailed in the October 2025 Critical Patch Update (CPU), affect the Core component of VirtualBox versions 7.1.12 and 7.2.2,…

  • TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes

    TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes A severe vulnerability in the async-tar Rust library and its popular forks, including the widely used tokio-tar. Dubbed TARmageddon and tracked as CVE-2025-62518, the bug carries a CVSS score of 8.1, classifying it as high severity. It allows attackers to manipulate…

  • Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset

    Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments. These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically targeting Microsoft Entra…

  • Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code

    Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code Google has swiftly addressed a high-severity flaw in its Chrome browser’s V8 JavaScript engine, releasing an emergency update to thwart potential remote code execution attacks. The vulnerability, tracked as CVE-2025-12036, stems from an inappropriate implementation within V8, the open-source JavaScript and WebAssembly engine powering Chrome’s…

  • Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable

    Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable Threat actors infiltrated the official Xubuntu website, redirecting torrent downloads to a malicious ZIP file containing Windows-targeted malware. The incident, uncovered on October 18, 2025, highlights vulnerabilities in community-maintained Linux distribution sites amid rising interest in alternatives to end-of-life operating systems. Users attempting to grab…

  • Pakistani Threat Actors Targeting Indian Govt. With Email Mimic as ‘NIC eEmail Services’

    Pakistani Threat Actors Targeting Indian Govt. With Email Mimic as ‘NIC eEmail Services’ A sophisticated phishing campaign orchestrated by Pakistan-linked threat actors has been discovered targeting Indian government entities by impersonating the National Informatics Centre’s email services. The operation, attributed to APT36, also known as TransparentTribe, leverages social engineering tactics to compromise sensitive government infrastructure…

  • Threat Actors Leverage npm Ecosystem to Deliver AdaptixC2 Post-Exploitation Framework

    Threat Actors Leverage npm Ecosystem to Deliver AdaptixC2 Post-Exploitation Framework The emergence of the AdaptixC2 post-exploitation framework in 2025 marked a significant milestone in the evolution of attacker toolsets targeting open-source supply chains. Positioning itself as a formidable alternative to established tools like Cobalt Strike, AdaptixC2 quickly attracted threat actors seeking agility and stealth in…

  • Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT

    Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT A sophisticated threat campaign has emerged targeting Russia’s public sector and critical industries between May and August 2025. The Cavalry Werewolf APT group, also known as YoroTrooper and Silent Lynx, has been actively deploying custom-built malware toolsets through highly targeted phishing operations that exploit…

  • Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely

    Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Microsoft has disclosed a serious security flaw in ASP.NET Core that enables authenticated attackers to smuggle HTTP requests and evade critical protections. Tracked as CVE-2025-55315, the vulnerability stems from inconsistent handling of HTTP requests, a classic issue known as HTTP request/response smuggling. Released on October…

  • ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

    ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration A critical vulnerability in Zyxel’s ATP and USG series firewalls that allows attackers to bypass authorization controls and access sensitive system configurations. Dubbed CVE-2025-9133, this flaw affects devices running firmware versions up to V5.40(ABPS.0) and enables unauthorized viewing and downloading of configs even during…

  • Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily

    Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily A persistent campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with attackers deploying over 30,000 new IP addresses daily to exploit timing-based vulnerabilities. This coordinated effort, linked to a global botnet, has seen unique IPs surge past 500,000 since September 2025, primarily aiming…

  • AWS Declares Major Outage Resolved After Nearly 24 Hours of Disruption

    AWS Declares Major Outage Resolved After Nearly 24 Hours of Disruption Amazon Web Services (AWS), the world’s largest cloud computing provider, has officially marked a widespread outage in its US-EAST-1 region as resolved, following nearly a full day of cascading failures that disrupted services for millions worldwide. The incident, which began late on October 19,…

  • Automatic BitLocker Encryption May Silently Lock Away Your Data

    Automatic BitLocker Encryption May Silently Lock Away Your Data A Reddit poster detailed how reinstalling Windows 11 unexpectedly encrypted two of their backup drives with BitLocker, locking away 3TB of irreplaceable data without any prior setup. The incident, shared onReddit, highlights the risks of Microsoft’s automatic encryption feature in Windows 11, which can activate silently…

  • AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More – Update

    AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More – Update A widespread Amazon Web Services (AWS) outage on Monday disrupted operations for millions of users worldwide, knocking out access to everything from streaming giants to social media platforms and financial apps. The incident, which began early in the morning, affected high-profile services like…

  • Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

    Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android A critical zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software has been disclosed, allowing attackers to execute malicious code remotely via seemingly innocuous audio messages. Google Project Zero’s Ivan Fratric and Natalie Silvanovich have identified an out-of-bounds write flaw in…

  • PoC Exploit Released for Windows Server Update Services Remote Code Execution Vulnerability

    PoC Exploit Released for Windows Server Update Services Remote Code Execution Vulnerability A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Microsoft’s Windows Server Update Services (WSUS), enabling unauthenticated attackers to execute remote code with SYSTEM privileges on affected servers. Dubbed CVE-2025-59287 and assigned a CVSS v3.1 score of 9.8, the flaw…

  • Canva Down – Suffers Global Outage, Leaving Millions of Users Unable to Access Platform

    Canva Down – Suffers Global Outage, Leaving Millions of Users Unable to Access Platform Canva, the popular graphic design platform, is reeling from a widespread outage that has rendered its services inaccessible to millions of users worldwide. As of 19:16 AEDT (02:46 IST), the platform’s status page reports “significantly increased error rates” impacting nearly all…

  • New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

    New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files into antivirus executable folders, potentially enabling malware persistence and evasion. Developed by cybersecurity expert Two Seven One Three, the tool demonstrates a novel technique for penetration testers…

  • New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft

    New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft Threat actors are leveraging Microsoft Azure Blob Storage to craft highly convincing phishing sites that mimic legitimate Office 365 login portals, putting Microsoft 365 users at severe risk of credential theft. This method exploits trusted Microsoft infrastructure, making the attacks harder to spot as the…

  • American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

    American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite (EBS). The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing enterprise software in the aviation sector.…

  • Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode

    Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode Microsoft’s latest security update has rendered USB keyboards and mice inoperable within the Windows Recovery Environment (WinRE). Released on October 14, 2025, as KB5066835 for OS Build 26100.6899, the patch affects Windows 11 versions 24H2 and 25H2, as well as Windows Server 2025. The…

  • Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft

    Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft Volkswagen Group has issued a statement addressing claims by the ransomware group 8Base, which alleges it has stolen and leaked sensitive data from the automaker. The German carmaker maintains that its core IT infrastructure remains unaffected; however, the company’s vague response leaves questions…

  • Authorities Dismantle Cybercrime-as-a-Service Platform, Seize 40,000 Active SIM Cards

    Authorities Dismantle Cybercrime-as-a-Service Platform, Seize 40,000 Active SIM Cards An international law enforcement operation has dismantled a large-scale cybercrime-as-a-service network responsible for fueling thousands of online fraud cases across Europe. The operation, known as SIMCARTEL, took place on 10 October 2025 in Latvia and resulted in five arrests, the seizure of key infrastructure, and the…

  • PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution

    PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution A proof-of-concept exploit for two critical vulnerabilities in the popular file archiver 7-Zip, potentially allowing attackers to execute arbitrary code remotely through malicious ZIP files. The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, were disclosed by the Zero Day Initiative (ZDI) on October 7, 2025, and…

  • Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution

    Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution Cybercriminals are exploiting TikTok’s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing malicious PowerShell…

  • Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections

    Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections Microsoft’s October 2025 cumulative update for Windows 11 has disrupted localhost functionality, preventing developers and users from accessing local web applications and services via 127.0.0.1. The issue, tied to update KB5066835 released on October 14, affects builds like 26100.6899 and has sparked widespread complaints on forums,…

  • Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data

    Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data A newly disclosed Server-Side Request Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major security concerns, prompting administrators to patch systems immediately. The issue, identified in the chat proxy configuration component, could allow attackers to gain unauthorized access to internal resources and sensitive user data.…

  • VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support

    VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support VMware has launched Workstation 25H2 and Fusion 25H2, the newest iterations of its desktop hypervisors, featuring a revamped versioning system, enhanced tools, and broader compatibility with modern hardware and operating systems. These updates aim to streamline virtualization for developers, IT professionals, and…

  • Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code

    Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code Cisco has disclosed a severe vulnerability in its widely used IOS and IOS XE Software, potentially allowing attackers to crash devices or seize full control through remote code execution. The flaw, rooted in the Simple Network Management Protocol (SNMP) subsystem, stems from a…

  • F5 Released Security Updates Covering Multiple Products Following Recent Hack

    F5 Released Security Updates Covering Multiple Products Following Recent Hack F5 Networks, a leading provider of application security and delivery solutions, has disclosed a significant security breach involving a nation-state threat actor, prompting the release of critical updates for its core products. Detected in August 2025, the incident exposed internal systems to prolonged unauthorized access,…

  • Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk

    Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk Over 269,000 F5 devices are reportedly exposed to the public internet daily, according to data from The Shadowserver Foundation. This exposure comes at a critical time following F5’s disclosure of a sophisticated nation-state attack that compromised its development environment, stealing source code…

  • North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency

    North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency In recent months, a sophisticated malware campaign—dubbed EtherHiding—has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide. The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, with attackers shifting tactics…

  • New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer

    New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer A sophisticated banking Trojan named Maverick has emerged in Brazil, leveraging WhatsApp as its primary distribution channel to compromise thousands of users. The malware campaign was detected in mid-October 2025, with cybersecurity solutions blocking over 62,000 infection attempts in just the first…

  • Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature

    Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature Microsoft has disclosed two critical vulnerabilities in its Windows BitLocker encryption feature, allowing attackers with physical access to bypass security protections and access encrypted data. Released on October 14, 2025, as part of the latest Patch Tuesday updates, these flaws, tracked as CVE-2025-55338 and CVE-2025-55333, pose a…

  • CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks

    CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe code execution vulnerability in Adobe Experience Manager Forms, urging organizations to patch immediately. Tracked as CVE-2025-54253, this flaw affects the Java Enterprise Edition (JEE) version of the software…

  • Critical Samba RCE Vulnerability Enables Arbitrary Code Execution

    Critical Samba RCE Vulnerability Enables Arbitrary Code Execution Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack Active Directory domain controllers. Tracked as CVE-2025-10230, the vulnerability stems from improper validation in the Windows Internet Name Service (WINS) hook mechanism, earning a perfect CVSS 3.1 score of 10.0 for…

  • Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File

    Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File Microsoft announced that it had revoked more than 200 digital certificates exploited by the notorious Vanilla Tempest hacking group. This action effectively disrupted an ongoing campaign where attackers impersonated Microsoft Teams installations to infiltrate corporate networks and deploy ransomware. The operation,…

  • Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code

    Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code Microsoft has disclosed a critical remote code execution flaw in its Internet Information Services (IIS) platform, posing risks to organizations relying on Windows servers for web hosting. Tracked as CVE-2025-59282, the vulnerability affects the Inbox COM Objects handling global memory, stemming from a race condition…

  • NCSC Warns of UK Experiencing Four Cyber Attacks Every Week

    NCSC Warns of UK Experiencing Four Cyber Attacks Every Week The United Kingdom faces an unprecedented cyber security crisis as the National Cyber Security Centre (NCSC) reports handling an average of four ‘nationally significant’ cyber attacks weekly. This alarming escalation represents a dangerous shift in the threat landscape, with the NCSC managing 204 nationally significant…

  • Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges

    Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges Microsoft has disclosed two critical zero-day vulnerabilities in the Agere Modem driver bundled with Windows operating systems, confirming active exploitation to escalate privileges. The flaws, tracked as CVE-2025-24990 and CVE-2025-24052, affect the ltmdm64.sys driver and could allow low-privileged attackers to gain full administrator access.…

  • Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code

    Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code Microsoft has patched a critical flaw in its Remote Desktop Client that could allow attackers to execute malicious code on victims’ systems. Disclosed on October 14, 2025, as CVE-2025-58718, the vulnerability stems from a use-after-free error, earning an “Important” severity rating. While not yet exploited…

  • Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely

    Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely Veeam Software has disclosed three serious security flaws in its Backup & Replication suite and Agent for Microsoft Windows, which enable remote code execution and privilege escalation, potentially compromising enterprise backup infrastructures. These vulnerabilities, patched in recent updates, primarily affect domain-joined systems in version…

  • Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands

    Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 under advisory ESA-2025-21, the flaw stems from improper neutralization of special elements in the Jinjava template…

  • New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

    New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide. CVE-2025-32463 targets the chroot feature in Sudo versions 1.9.14 through 1.9.17, enabling local attackers to escalate privileges…

  • Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access

    Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer logs for unauthorized system entry. This transition marks a significant change…

  • Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials

    Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services. The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded…

  • Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads

    Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations. The attack exploits the widespread trust users place in the popular Homebrew package manager by creating pixel-perfect replicas of the official…

  • SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

    SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups A surge in attacks targeting SonicWall SSLVPN devices, affecting numerous customer networks, just weeks after a major breach exposed sensitive firewall data. Starting October 4, 2025, threat actors have rapidly authenticated into over 100 accounts across 16 environments, using what appear to be…

  • RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks

    RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks An open-source tool called RealBlindingEDR enables attackers to blind, permanently disable, or terminate antivirus (AV) and endpoint detection and response (EDR) software by clearing critical kernel callbacks on Windows systems. Released on GitHub in late 2023, the utility leverages signed drivers for arbitrary memory read…

  • Cybersecurity Newsletter Weekly – Discord, Red Hat Data Breach, 7-Zip Vulnerabilities and Sonicwall Firewall Hack

    Cybersecurity Newsletter Weekly – Discord, Red Hat Data Breach, 7-Zip Vulnerabilities and Sonicwall Firewall Hack Welcome to this week’s edition of the Cybersecurity Newsletter Weekly, where we dive into the most pressing threats and vulnerabilities shaping the digital landscape. As cyber risks continue to evolve at breakneck speed, our October 12, 2025, roundup spotlights a…

  • Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication

    Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations. Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed…

  • Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor

    Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor A new technique enables attackers to exploit antivirus software by injecting harmful code directly into the antivirus processes. This approach makes it easier for them to evade detection and compromise the security that antivirus software is designed to provide. This method, detailed by…

  • VirusTotal Simplifies User Options With Platform Access and New Contributor Model

    VirusTotal Simplifies User Options With Platform Access and New Contributor Model VirusTotal (VT) is making important changes to its platform access and pricing. These updates aim to improve accessibility and strengthen its commitment to collaboration. The initiative, detailed in a recent company announcement, aims to simplify user options while reinforcing VT’s commitment to the global…

  • 5 Immediate Steps to be Followed After Clicking on a Malicious Link

    5 Immediate Steps to be Followed After Clicking on a Malicious Link Clicking on a malicious link can quickly turn your device into a security risk. Just seconds after clicking, your browser might start downloading malware, taking advantage of weaknesses, or sending you to fake websites that try to steal your personal information. The crucial…

  • Microsoft Fixes Long-standing Windows 11 ‘Update and Shut down’ Bug

    Microsoft Fixes Long-standing Windows 11 ‘Update and Shut down’ Bug Microsoft has rolled out a fix in its latest preview builds to resolve a notorious glitch with the “update and shut down” feature. This long-standing issue, which has haunted the operating system for years, tricked users into believing their PCs were powering off when updates were pending, only for the machines to restart unexpectedly and disrupt sleep cycles with noisy fans. The bug emerged shortly after Windows…

  • Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files

    Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files Critical flaws uncovered in the network communication between Microsoft Defender for Endpoint (DFE) and its cloud services, allowing post-breach attackers to bypass authentication, spoof data, disclose sensitive information, and even upload malicious files to investigation packages. These vulnerabilities, detailed in a recent analysis…

  • New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities

    New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities Along with the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the llm-tools-nmap. A new experimental plugin, llm-tools-nmap, has been released, providing Simon Willison’s command-line Large Language Model (LLM) tool with network scanning capabilities. This package…

  • Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

    Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native Application Protection Platforms (CNAPP), is proud to announce that Nanoprecise has selected AccuKnox to enhance its cloud security, governance, and compliance framework. Nanoprecise is a pioneer…

  • Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

    Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks. Beginning in July, multiple incidents of initial access via unpatched SonicWall devices were reported across North America and EMEA. Attackers…

  • New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

    New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial investigations revealed that threat actors gained entry by exploiting compromised CiscoVPN credentials coupled with over-privileged Active Directory service accounts. Once inside, ChaosBot was stealthily deployed via side-loading techniques…

  • 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

    175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across all packages, represents a novel abuse of npm’s public registry and the…

  • SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data

    SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data Emerging from a recent wave of targeted campaigns, SnakeKeylogger has surfaced as a potent infostealer that capitalizes on PowerShell and social engineering. The malware’s operators craft convincing spear-phishing e-mails under aliases such as “CPA-Payment Files,” impersonating reputable financial and research firms. Recipients encounter ISO or…

  • LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code

    LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code Cybersecurity researchers have identified what is believed to be the earliest known instance of malware that leverages a Large Language Model (LLM) to generate malicious code at runtime. Dubbed ‘MalTerminal’ by SentinelLABS, the malware uses OpenAI’s GPT-4 to dynamically create ransomware code and reverse shells, presenting…

  • New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users

    New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users A sophisticated Android spyware campaign dubbed ClayRat has emerged as one of the most concerning mobile threats of 2025, masquerading as popular applications including WhatsApp, Google Photos, TikTok, and YouTube to infiltrate devices and steal sensitive user data. The malware demonstrates remarkable adaptability…

  • Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks

    Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks An active in-the-wild exploitation of a zero-day vulnerability in Gladinet CentreStack and Triofox products. Tracked as CVE-2025-11371, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems. The vulnerability is currently unpatched, but a mitigation has…

  • Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments

    Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments A sophisticated financially motivated threat actor known as Storm-2657 has been orchestrating elaborate “payroll pirate” attacks targeting US universities and other organizations, Microsoft Threat Intelligence has revealed. These attacks represent a concerning evolution in cybercriminal tactics, where hackers compromise employee accounts to gain unauthorized…

  • GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack

    GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could lead to denial-of-service (DoS) attacks and allow unauthorized access. All self-managed GitLab installations…

  • Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released

    Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released Security researchers have released a full proof-of-concept (PoC) exploit for a high-severity vulnerability in the Linux kernel’s ksmbd module, demonstrating a reliable path to local privilege escalation. The vulnerability, tracked as CVE-2025-37947, is an out-of-bounds write that can be leveraged by an authenticated local attacker to…

  • Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated

    Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated A significant Microsoft 365 outage blocked user access to several critical services, including Microsoft Teams, Exchange Online, and the Microsoft 365 admin center. The incident began late on Wednesday, October 8, 2025, leaving organizations worldwide unable to utilize essential communication and…

  • Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack

    Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading style sheets (CSS) properties. This attack vector enables threat actors…

  • IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

    IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond. Initially focused on credential harvesting via targeted phishing campaigns, the group has evolved…

  • Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

    Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP code injections within theme files to serve unwanted third-party scripts. The attack blends seamlessly with…

  • Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware

    Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware Microsoft has issued a warning that both cybercriminals and state-sponsored threat actors are increasingly abusing the features and capabilities of Microsoft Teams throughout their attack chains. The extensive collaboration features and global adoption of Microsoft Teams make it a high-value target for both…

  • Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks

    Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, along with 141.0.7390.65 for Linux, addressing multiple critical security vulnerabilities that could allow attackers to execute arbitrary code on affected systems.  The update, announced on October 7, 2025, includes three significant security fixes that pose…

  • Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs

    Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs A massive escalation in attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals, with over 2,200 unique IP addresses conducting reconnaissance operations as of October 7, 2025.  This represents a significant surge from the initial 1,300 IPs observed just days earlier, marking…

  • CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

    CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915.  This vulnerability has been actively exploited in attacks and poses significant risks to organizations using the popular email and…

  • CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks

    CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks CISA has issued an urgent security advisory, adding Microsoft Windows privilege escalation vulnerability CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025.  The vulnerability affects the Microsoft Windows Common Log File System (CLFS) Driver and poses significant security risks to enterprise environments.…

  • Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials

    Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Elastic has released a security advisory detailing a medium-severity vulnerability in the Kibana CrowdStrike Connector that could allow for the exposure of sensitive credentials. The flaw, tracked as CVE-2025-37728, affects multiple versions of Kibana and could allow a malicious user to access cached CrowdStrike credentials from other users…

  • GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware

    GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware A critical deserialization flaw in GoAnywhere MFT’s License Servlet, tracked as CVE-2025-10035, has already been weaponized by the Storm-1175 group to execute the Medusa ransomware. The vulnerability affects GoAnywhere MFT versions up to 7.8.3. It resides in the License Servlet Admin Console, where…

  • Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

    Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch their systems.  The vulnerability, carrying a maximum CVSS score of 9.8, affects the…

  • OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released

    OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim’s machine. The vulnerability is a bypass of a previous fix for a similar issue (CVE-2023-51385) and exploits…