Category: CyberSecurityNews

WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File
29
Sep
2025

WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File

WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple’s iOS, macOS, and iPadOS platforms, detailed with a proof of concept…

Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information
29
Sep
2025

Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information

In recent weeks, a sophisticated phishing campaign has emerged, targeting organizations in Ukraine with malicious Scalable Vector Graphics (SVG) files…

Windows Heap Exploitation Vulnerability With Record's Size Field Leads to Arbitrary R/W
29
Sep
2025

Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W

A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write…

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization
29
Sep
2025

Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization

A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead…

DataCenter Fire Takes 600+ South Korean Government Websites Offline
29
Sep
2025

DataCenter Fire Takes 600+ South Korean Government Websites Offline

A fire caused by a lithium-ion battery explosion at a key government data center in South Korea has knocked more…

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes
29
Sep
2025

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes

Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish…

Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code
29
Sep
2025

Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code

A newly discovered DLL hijacking vulnerability in Notepad++, the popular source code editor, could allow attackers to execute arbitrary code…

Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization
28
Sep
2025

Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization

A Google Project Zero researcher has detailed a novel technique for remotely leaking memory addresses on Apple’s macOS and iOS….

Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations
27
Sep
2025

Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations

A sophisticated cybercriminal alliance between malware operators and covert North Korean IT workers has emerged as a significant threat to…

Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware
27
Sep
2025

Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware

A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search engine results and…

Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users
27
Sep
2025

Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users

A critical security flaw has emerged in Apache Airflow 3.0.3, exposing sensitive connection information to users with only read permissions….

New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads
27
Sep
2025

New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads

A sophisticated botnet operation has emerged, employing a Loader-as-a-Service model to systematically weaponize internet-connected devices across the globe. The campaign…