Category: CyberSecurityNews

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature
11
Nov
2025

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster…

SAP Security Update - Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks
11
Nov
2025

SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones,…

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks
11
Nov
2025

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat…

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware
11
Nov
2025

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote…

Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO
10
Nov
2025

Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO

Cybercriminals are increasingly targeting websites to inject malicious links and boost their search engine optimization rankings through sophisticated blackhat SEO…

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case
10
Nov
2025

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case

Francesco Nicodemo, a prominent political communications strategist and former Democratic Party communications director, has been identified as a new target…

APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins
10
Nov
2025

APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins

The construction industry has emerged as a lucrative target for advanced persistent threat groups and organized cybercriminal networks seeking unauthorized…

Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List
10
Nov
2025

Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List

In early November 2025, Knownsec, one of China’s largest cybersecurity firms with direct government ties, experienced a catastrophic data breach…

Incident Response Team ShieldForce Partners with AccuKnox to Deliver Zero Trust CNAPP in Latin America
10
Nov
2025

Incident Response Team ShieldForce Partners with AccuKnox to Deliver Zero Trust CNAPP in Latin America

Menlo Park, CA, USA, November 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), announced…

OWASP Top 10 2025 - Revised Version Released With Two New Categories
10
Nov
2025

OWASP Top 10 2025 – Revised Version Released With Two New Categories

The Open Web Application Security Project (OWASP) has unveiled the 2025 edition of its flagship OWASP Top 10 2025, marking…

LangGraph Vulnerability Allows Malicious Python Code Execution During Deserialization
10
Nov
2025

LangGraph Vulnerability Allows Malicious Python Code Execution During Deserialization

A critical remote code execution vulnerability has been discovered in LangGraph’s checkpoint serialization system. The flaw CVE-2025-64439 affects versions of…

Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution
10
Nov
2025

Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution

A critical security flaw has been discovered in the widely used npm package expr-eval, potentially exposing AI and natural language…