Category: Cyber Security
-
Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android
Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android A critical zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software has been disclosed, allowing attackers to execute malicious code remotely via seemingly innocuous audio messages. Google Project Zero’s Ivan Fratric and Natalie Silvanovich have identified an out-of-bounds write flaw in…
-
PoC Exploit Released for Windows Server Update Services Remote Code Execution Vulnerability
PoC Exploit Released for Windows Server Update Services Remote Code Execution Vulnerability A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Microsoft’s Windows Server Update Services (WSUS), enabling unauthenticated attackers to execute remote code with SYSTEM privileges on affected servers. Dubbed CVE-2025-59287 and assigned a CVSS v3.1 score of 9.8, the flaw…
-
Canva Down – Suffers Global Outage, Leaving Millions of Users Unable to Access Platform
Canva Down – Suffers Global Outage, Leaving Millions of Users Unable to Access Platform Canva, the popular graphic design platform, is reeling from a widespread outage that has rendered its services inaccessible to millions of users worldwide. As of 19:16 AEDT (02:46 IST), the platform’s status page reports “significantly increased error rates” impacting nearly all…
-
New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders
New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files into antivirus executable folders, potentially enabling malware persistence and evasion. Developed by cybersecurity expert Two Seven One Three, the tool demonstrates a novel technique for penetration testers…
-
New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft
New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft Threat actors are leveraging Microsoft Azure Blob Storage to craft highly convincing phishing sites that mimic legitimate Office 365 login portals, putting Microsoft 365 users at severe risk of credential theft. This method exploits trusted Microsoft infrastructure, making the attacks harder to spot as the…
-
American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign
American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite (EBS). The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing enterprise software in the aviation sector.…
-
Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft
Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft Volkswagen Group has issued a statement addressing claims by the ransomware group 8Base, which alleges it has stolen and leaked sensitive data from the automaker. The German carmaker maintains that its core IT infrastructure remains unaffected; however, the company’s vague response leaves questions…
-
Authorities Dismantle Cybercrime-as-a-Service Platform, Seize 40,000 Active SIM Cards
Authorities Dismantle Cybercrime-as-a-Service Platform, Seize 40,000 Active SIM Cards An international law enforcement operation has dismantled a large-scale cybercrime-as-a-service network responsible for fueling thousands of online fraud cases across Europe. The operation, known as SIMCARTEL, took place on 10 October 2025 in Latvia and resulted in five arrests, the seizure of key infrastructure, and the…
-
PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution
PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution A proof-of-concept exploit for two critical vulnerabilities in the popular file archiver 7-Zip, potentially allowing attackers to execute arbitrary code remotely through malicious ZIP files. The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, were disclosed by the Zero Day Initiative (ZDI) on October 7, 2025, and…
-
Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution
Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution Cybercriminals are exploiting TikTok’s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing malicious PowerShell…
-
Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections
Microsoft Windows 11 October Update Breaks Localhost (127.0.0.1) Connections Microsoft’s October 2025 cumulative update for Windows 11 has disrupted localhost functionality, preventing developers and users from accessing local web applications and services via 127.0.0.1. The issue, tied to update KB5066835 released on October 14, affects builds like 26100.6899 and has sparked widespread complaints on forums,…
-
Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data
Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data A newly disclosed Server-Side Request Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major security concerns, prompting administrators to patch systems immediately. The issue, identified in the chat proxy configuration component, could allow attackers to gain unauthorized access to internal resources and sensitive user data.…
-
VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support
VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support VMware has launched Workstation 25H2 and Fusion 25H2, the newest iterations of its desktop hypervisors, featuring a revamped versioning system, enhanced tools, and broader compatibility with modern hardware and operating systems. These updates aim to streamline virtualization for developers, IT professionals, and…
-
Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code
Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code Cisco has disclosed a severe vulnerability in its widely used IOS and IOS XE Software, potentially allowing attackers to crash devices or seize full control through remote code execution. The flaw, rooted in the Simple Network Management Protocol (SNMP) subsystem, stems from a…
-
F5 Released Security Updates Covering Multiple Products Following Recent Hack
F5 Released Security Updates Covering Multiple Products Following Recent Hack F5 Networks, a leading provider of application security and delivery solutions, has disclosed a significant security breach involving a nation-state threat actor, prompting the release of critical updates for its core products. Detected in August 2025, the incident exposed internal systems to prolonged unauthorized access,…
-
Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk
Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk Over 269,000 F5 devices are reportedly exposed to the public internet daily, according to data from The Shadowserver Foundation. This exposure comes at a critical time following F5’s disclosure of a sophisticated nation-state attack that compromised its development environment, stealing source code…
-
North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency
North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency In recent months, a sophisticated malware campaign—dubbed EtherHiding—has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide. The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, with attackers shifting tactics…
-
New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer
New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer A sophisticated banking Trojan named Maverick has emerged in Brazil, leveraging WhatsApp as its primary distribution channel to compromise thousands of users. The malware campaign was detected in mid-October 2025, with cybersecurity solutions blocking over 62,000 infection attempts in just the first…
-
CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks
CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe code execution vulnerability in Adobe Experience Manager Forms, urging organizations to patch immediately. Tracked as CVE-2025-54253, this flaw affects the Java Enterprise Edition (JEE) version of the software…
-
Critical Samba RCE Vulnerability Enables Arbitrary Code Execution
Critical Samba RCE Vulnerability Enables Arbitrary Code Execution Samba has disclosed a severe remote code execution (RCE) flaw that could allow attackers to hijack Active Directory domain controllers. Tracked as CVE-2025-10230, the vulnerability stems from improper validation in the Windows Internet Name Service (WINS) hook mechanism, earning a perfect CVSS 3.1 score of 10.0 for…
-
Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File
Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File Microsoft announced that it had revoked more than 200 digital certificates exploited by the notorious Vanilla Tempest hacking group. This action effectively disrupted an ongoing campaign where attackers impersonated Microsoft Teams installations to infiltrate corporate networks and deploy ransomware. The operation,…
-
Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code
Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code Microsoft has disclosed a critical remote code execution flaw in its Internet Information Services (IIS) platform, posing risks to organizations relying on Windows servers for web hosting. Tracked as CVE-2025-59282, the vulnerability affects the Inbox COM Objects handling global memory, stemming from a race condition…
-
NCSC Warns of UK Experiencing Four Cyber Attacks Every Week
NCSC Warns of UK Experiencing Four Cyber Attacks Every Week The United Kingdom faces an unprecedented cyber security crisis as the National Cyber Security Centre (NCSC) reports handling an average of four ‘nationally significant’ cyber attacks weekly. This alarming escalation represents a dangerous shift in the threat landscape, with the NCSC managing 204 nationally significant…
-
Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges
Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges Microsoft has disclosed two critical zero-day vulnerabilities in the Agere Modem driver bundled with Windows operating systems, confirming active exploitation to escalate privileges. The flaws, tracked as CVE-2025-24990 and CVE-2025-24052, affect the ltmdm64.sys driver and could allow low-privileged attackers to gain full administrator access.…
-
Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code
Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code Microsoft has patched a critical flaw in its Remote Desktop Client that could allow attackers to execute malicious code on victims’ systems. Disclosed on October 14, 2025, as CVE-2025-58718, the vulnerability stems from a use-after-free error, earning an “Important” severity rating. While not yet exploited…
-
Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely
Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely Veeam Software has disclosed three serious security flaws in its Backup & Replication suite and Agent for Microsoft Windows, which enable remote code execution and privilege escalation, potentially compromising enterprise backup infrastructures. These vulnerabilities, patched in recent updates, primarily affect domain-joined systems in version…
-
Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access
Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer logs for unauthorized system entry. This transition marks a significant change…
-
Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands
Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 under advisory ESA-2025-21, the flaw stems from improper neutralization of special elements in the Jinjava template…
-
New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability
New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide. CVE-2025-32463 targets the chroot feature in Sudo versions 1.9.14 through 1.9.17, enabling local attackers to escalate privileges…
-
Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials
Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services. The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded…
-
Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads
Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations. The attack exploits the widespread trust users place in the popular Homebrew package manager by creating pixel-perfect replicas of the official…
-
SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups
SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups A surge in attacks targeting SonicWall SSLVPN devices, affecting numerous customer networks, just weeks after a major breach exposed sensitive firewall data. Starting October 4, 2025, threat actors have rapidly authenticated into over 100 accounts across 16 environments, using what appear to be…
-
RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks
RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks An open-source tool called RealBlindingEDR enables attackers to blind, permanently disable, or terminate antivirus (AV) and endpoint detection and response (EDR) software by clearing critical kernel callbacks on Windows systems. Released on GitHub in late 2023, the utility leverages signed drivers for arbitrary memory read…
-
Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication
Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations. Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed…
-
VirusTotal Simplifies User Options With Platform Access and New Contributor Model
VirusTotal Simplifies User Options With Platform Access and New Contributor Model VirusTotal (VT) is making important changes to its platform access and pricing. These updates aim to improve accessibility and strengthen its commitment to collaboration. The initiative, detailed in a recent company announcement, aims to simplify user options while reinforcing VT’s commitment to the global…
-
Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor
Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor A new technique enables attackers to exploit antivirus software by injecting harmful code directly into the antivirus processes. This approach makes it easier for them to evade detection and compromise the security that antivirus software is designed to provide. This method, detailed by…
-
5 Immediate Steps to be Followed After Clicking on a Malicious Link
5 Immediate Steps to be Followed After Clicking on a Malicious Link Clicking on a malicious link can quickly turn your device into a security risk. Just seconds after clicking, your browser might start downloading malware, taking advantage of weaknesses, or sending you to fake websites that try to steal your personal information. The crucial…
-
Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files
Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files Critical flaws uncovered in the network communication between Microsoft Defender for Endpoint (DFE) and its cloud services, allowing post-breach attackers to bypass authentication, spoof data, disclose sensitive information, and even upload malicious files to investigation packages. These vulnerabilities, detailed in a recent analysis…
-
New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities
New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities Along with the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the llm-tools-nmap. A new experimental plugin, llm-tools-nmap, has been released, providing Simon Willison’s command-line Large Language Model (LLM) tool with network scanning capabilities. This package…
-
175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide
175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across all packages, represents a novel abuse of npm’s public registry and the…
-
Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware
Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks. Beginning in July, multiple incidents of initial access via unpatched SonicWall devices were reported across North America and EMEA. Attackers…
-
New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands
New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial investigations revealed that threat actors gained entry by exploiting compromised CiscoVPN credentials coupled with over-privileged Active Directory service accounts. Once inside, ChaosBot was stealthily deployed via side-loading techniques…
-
SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data
SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data Emerging from a recent wave of targeted campaigns, SnakeKeylogger has surfaced as a potent infostealer that capitalizes on PowerShell and social engineering. The malware’s operators craft convincing spear-phishing e-mails under aliases such as “CPA-Payment Files,” impersonating reputable financial and research firms. Recipients encounter ISO or…
-
LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code
LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code Cybersecurity researchers have identified what is believed to be the earliest known instance of malware that leverages a Large Language Model (LLM) to generate malicious code at runtime. Dubbed ‘MalTerminal’ by SentinelLABS, the malware uses OpenAI’s GPT-4 to dynamically create ransomware code and reverse shells, presenting…
-
New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users
New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users A sophisticated Android spyware campaign dubbed ClayRat has emerged as one of the most concerning mobile threats of 2025, masquerading as popular applications including WhatsApp, Google Photos, TikTok, and YouTube to infiltrate devices and steal sensitive user data. The malware demonstrates remarkable adaptability…
-
Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks
Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks An active in-the-wild exploitation of a zero-day vulnerability in Gladinet CentreStack and Triofox products. Tracked as CVE-2025-11371, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems. The vulnerability is currently unpatched, but a mitigation has…
-
Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments
Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments A sophisticated financially motivated threat actor known as Storm-2657 has been orchestrating elaborate “payroll pirate” attacks targeting US universities and other organizations, Microsoft Threat Intelligence has revealed. These attacks represent a concerning evolution in cybercriminal tactics, where hackers compromise employee accounts to gain unauthorized…
-
GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack
GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could lead to denial-of-service (DoS) attacks and allow unauthorized access. All self-managed GitLab installations…
-
Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released
Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released Security researchers have released a full proof-of-concept (PoC) exploit for a high-severity vulnerability in the Linux kernel’s ksmbd module, demonstrating a reliable path to local privilege escalation. The vulnerability, tracked as CVE-2025-37947, is an out-of-bounds write that can be leveraged by an authenticated local attacker to…
-
Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack
Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading style sheets (CSS) properties. This attack vector enables threat actors…
-
IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed
IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond. Initially focused on credential harvesting via targeted phishing campaigns, the group has evolved…
-
Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently
Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP code injections within theme files to serve unwanted third-party scripts. The attack blends seamlessly with…
-
Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware
Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware Microsoft has issued a warning that both cybercriminals and state-sponsored threat actors are increasingly abusing the features and capabilities of Microsoft Teams throughout their attack chains. The extensive collaboration features and global adoption of Microsoft Teams make it a high-value target for both…
-
Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks
Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, along with 141.0.7390.65 for Linux, addressing multiple critical security vulnerabilities that could allow attackers to execute arbitrary code on affected systems. The update, announced on October 7, 2025, includes three significant security fixes that pose…
-
Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs
Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs A massive escalation in attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals, with over 2,200 unique IP addresses conducting reconnaissance operations as of October 7, 2025. This represents a significant surge from the initial 1,300 IPs observed just days earlier, marking…
-
CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks
CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915. This vulnerability has been actively exploited in attacks and poses significant risks to organizations using the popular email and…
-
CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks
CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks CISA has issued an urgent security advisory, adding Microsoft Windows privilege escalation vulnerability CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025. The vulnerability affects the Microsoft Windows Common Log File System (CLFS) Driver and poses significant security risks to enterprise environments.…
-
Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials
Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Elastic has released a security advisory detailing a medium-severity vulnerability in the Kibana CrowdStrike Connector that could allow for the exposure of sensitive credentials. The flaw, tracked as CVE-2025-37728, affects multiple versions of Kibana and could allow a malicious user to access cached CrowdStrike credentials from other users…
-
GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware
GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware A critical deserialization flaw in GoAnywhere MFT’s License Servlet, tracked as CVE-2025-10035, has already been weaponized by the Storm-1175 group to execute the Medusa ransomware. The vulnerability affects GoAnywhere MFT versions up to 7.8.3. It resides in the License Servlet Admin Console, where…
-
Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild
Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch their systems. The vulnerability, carrying a maximum CVSS score of 9.8, affects the…
-
OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released
OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim’s machine. The vulnerability is a bypass of a previous fix for a similar issue (CVE-2023-51385) and exploits…
-
Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks
Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks With the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the Gemini Command-Line Interface (CLI). This new open-source package integrates Google’s powerful Gemini AI directly into the terminal, offering penetration testers and security…
-
Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server
Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server A sophisticated technique uncovered where threat actors abuse Amazon Web Services‘ X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be weaponized for malicious purposes. AWS X-Ray, designed to help developers analyze application…
-
Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution
Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that utilize the Lua scripting engine, presenting a significant threat to a wide range of deployments that…
-
PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access
PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access A publicly available proof-of-concept (PoC) exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) flaw in the Sudo utility that can grant root access under specific configurations. Security researcher Rich Mirch is credited with identifying the weakness, while a functional…
-
Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code
Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code Unity Technologies has issued a critical security advisory warning developers about a high-severity vulnerability affecting its widely used game development platform. The flaw, designated CVE-2025-59489, exposes applications built with vulnerable Unity Editor versions to unsafe file loading attacks that could enable local code execution and…
-
New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data
New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data A newly disclosed vulnerability, named the WireTap attack, allows attackers with physical access to break the security of Intel’s Software Guard eXtensions (SGX) on modern server processors and steal sensitive information. A research paper released in October 2025 details how this method can extract cryptographic…
-
New CometJacking Attack Let Attackers Turn Perplexity Browser Against You in One Click
New CometJacking Attack Let Attackers Turn Perplexity Browser Against You in One Click A groundbreaking cybersecurity vulnerability has emerged that transforms Perplexity’s AI-powered Comet browser into an unintentional collaborator for data theft. Security researchers at LayerX have discovered a sophisticated attack vector dubbed “CometJacking” that enables malicious actors to weaponize a single URL to extract…
-
Microsoft to Disable Inline SVG Images Display to Outlook for Web and Windows Users
Microsoft to Disable Inline SVG Images Display to Outlook for Web and Windows Users Microsoft has announced a significant security enhancement for Outlook users, implementing the retirement of inline SVG image support across Outlook for Web and the new Outlook for Windows platforms. This change represents a proactive measure to strengthen email security infrastructure and…
-
Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data
Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data Renault UK has notified customers of a data breach after a cyberattack on one of its third-party service providers resulted in the theft of personal information. The company has assured its clients that its own internal systems were not compromised and that no financial…
-
Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site
Scattered LAPSUS$ Hunters Announced Salesforce Breach List On New Onion Site A cybercrime collective known as Scattered LAPSUS$ Hunters has launched a new data leak site on the dark web, claiming it holds nearly one billion records from Salesforce customers. The group is orchestrating a widespread blackmail campaign, setting a ransom deadline of October 10,…
-
Top 10 Best Supply Chain Intelligence Security Companies in 2025
Top 10 Best Supply Chain Intelligence Security Companies in 2025 The digital world continues to face growing threats around software vulnerabilities, data breaches, and cyber supply chain attacks. As companies rely more heavily on open-source software, third-party code, and cloud-native applications, the need for supply chain intelligence security solutions has never been greater. In 2025,…
-
Discord Data Breach – Customers Personal Data and Scanned Photo IDs leaked
Discord Data Breach – Customers Personal Data and Scanned Photo IDs leaked A data breach at a third-party customer service provider has exposed the personal data of some Discord users, including names, email addresses, and a small number of scanned government-issued photo IDs. The incident did not compromise Discord’s main systems, and the unauthorized access…
-
Top 10 Best Fraud Prevention Companies in 2025
Top 10 Best Fraud Prevention Companies in 2025 In 2025, digital transactions are at an all-time high, but so are the risks of fraud. Businesses in banking, e-commerce, fintech, and even social networks are facing increasing pressure to secure their platforms against identity theft, payment fraud, and cybersecurity threats. Fraud prevention tools have evolved into…
-
Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware
Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed AnonDoor. Historically known for deploying document stealers such as WooperStealer, the threat actor has now…
-
HackerOne Paid $81 In Bug Bounty With Emergence of Bionic Hackers
HackerOne Paid $81 In Bug Bounty With Emergence of Bionic Hackers HackerOne, a leading platform in offensive security, announced it has paid out a total of $81 million in bug bounties to its global community of white-hat hackers over the past year. This figure, detailed in the company’s 9th annual Hacker-Powered Security Report, marks a…
-
Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data
Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data Mobile VPN apps promise to protect privacy and secure communications on smartphones, but a comprehensive analysis of nearly 800 free Android and iOS VPN applications reveals a troubling reality: many of these tools expose sensitive information rather than shield it. From…
-
Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails
Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails Oracle Corporation has officially acknowledged that cybercriminals are targeting customers of its E-Business Suite (EBS) platform through sophisticated extortion campaigns. The company’s Chief Security Officer, Rob Duhart, confirmed that hackers have been exploiting previously identified vulnerabilities that were addressed in Oracle’s July 2025 Critical…
-
Signal Enhances Security With New Hybrid PQ Ratchet to Compact Quantum Computing Threats
Signal Enhances Security With New Hybrid PQ Ratchet to Compact Quantum Computing Threats Signal has announced a groundbreaking advancement in secure messaging with the introduction of the Sparse Post Quantum Ratchet (SPQR), a revolutionary cryptographic enhancement designed to protect against future quantum computing threats. This latest security upgrade represents a significant milestone in the evolution…
-
Ukraine Warns of Weaponized XLL Files Delivers CABINETRAT Malware Via Zip Files
Ukraine Warns of Weaponized XLL Files Delivers CABINETRAT Malware Via Zip Files Ukrainian security agencies have issued an urgent warning regarding a sophisticated malware campaign targeting government and critical infrastructure sectors through weaponized XLL files distributed via compressed archives. The malicious campaign leverages Microsoft Excel add-in files containing the CABINETRAT backdoor, representing a significant evolution…
-
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code Splunk has released patches for multiple vulnerabilities in its Enterprise and Cloud Platform products, some of which could allow attackers to execute unauthorized JavaScript code, access sensitive information, or cause a denial-of-service (DoS) condition. The advisories, published on October 1, 2025, detail six security flaws,…
-
Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser
Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code. The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that pose…
-
Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories
Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories An extortion group known as the Crimson Collective claims to have breached Red Hat’s private GitHub repositories, making off with nearly 570GB of compressed data from 28,000 internal repositories. This data theft is being regarded as one of the most significant…
-
Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details
Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details A sophisticated phishing campaign has emerged targeting job seekers through fake Google career recruitment opportunities, leveraging social engineering tactics to harvest Gmail credentials and personal information. The malicious operation exploits the trust associated with Google’s brand reputation, crafting convincing recruitment emails that direct victims…
-
Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links
Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links Hackers have recently leveraged a vulnerability in the web-based management interfaces of certain cellular routers to co-opt their built-in SMS functionality for nefarious purposes. By targeting exposed APIs, attackers are able to dispatch large volumes of malicious SMS messages containing weaponized links…
-
48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild
48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild. The vulnerability, tracked as CVE-2025-20333, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of the most severe…
-
Apple Font Parser Vulnerability Enables Malicious Fonts to Corrupt Process Memory
Apple Font Parser Vulnerability Enables Malicious Fonts to Corrupt Process Memory Apple has rolled out security updates across its operating systems to address a vulnerability in the Font Parser component that could allow malicious fonts to crash applications or corrupt process memory. The vulnerability, identified as CVE-2025-43400, affects a wide range of products, including the…
-
Critical Western Digital My Cloud NAS Vulnerability Allows Remote Code Execution
Critical Western Digital My Cloud NAS Vulnerability Allows Remote Code Execution Western Digital has released security updates for a critical vulnerability affecting multiple My Cloud network-attached storage (NAS) devices. The flaw, tracked as CVE-2025-30247, could allow a remote attacker to execute arbitrary code on vulnerable systems, potentially leading to a complete device takeover. The company…
-
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Disclosed on 29 September 2025, the advisory covers CVE-2025-41244, CVE-2025-41245, and CVE-2025-41246 with CVSSv3 base…
-
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker to gain root-level code execution on affected systems. On September 29, 2025,…
-
Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code
Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code A malicious npm package masquerading as the official Postmark MCP Server has been exfiltrating user emails to an external server. This fake “postmark-mcp” module, available on npm from versions 1.0.0 through 1.0.15, built trust over 15 incremental releases before…
-
Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization
Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead to complete account takeovers. The vulnerability tracked as CVE-2025-59934 affects all versions prior to 4.0.1 and stems from improper token validation that uses jwt.decode()…
-
Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes
Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish robust command and control infrastructure. These publicly rentable subdomain services, traditionally designed for legitimate hosting purposes, have become the preferred platform for threat actors…
-
Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information
Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information In recent weeks, a sophisticated phishing campaign has emerged, targeting organizations in Ukraine with malicious Scalable Vector Graphics (SVG) files designed to propagate the PureMiner cryptominer and a data-stealing payload dubbed Amatera Stealer. Attackers masquerade as the Ukrainian police, sending emails that claim…
-
Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W
Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write operations. Suraj Malhotra shared a detailed exploitation technique leveraging the Low Fragmentation Heap (LFH) mechanism to achieve code execution on Windows systems. Windows…
-
Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users
Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users A critical security flaw has emerged in Apache Airflow 3.0.3, exposing sensitive connection information to users with only read permissions. The vulnerability, tracked as CVE-2025-54831 and classified as “important” severity, fundamentally undermines the platform’s intended security model for handling sensitive data within workflow connections. Apache Airflow…
-
Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware
Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search engine results and abused code-signing certificates to deliver the Oyster backdoor malware. The attack was neutralized by Microsoft Defender’s Attack Surface Reduction (ASR) rules, which blocked…
-
Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization
Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization A Google Project Zero researcher has detailed a novel technique for remotely leaking memory addresses on Apple’s macOS and iOS. This method can bypass a key security feature, Address Space Layout Randomization (ASLR), without relying on traditional memory corruption vulnerabilities or timing-based side-channel…
-
Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations
Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations A sophisticated cybercriminal alliance between malware operators and covert North Korean IT workers has emerged as a significant threat to corporate organizations worldwide. This hybrid operation, known as DeceptiveDevelopment, represents a dangerous convergence of traditional cybercrime and state-sponsored activities, targeting software developers…