Category: CyberSecurityNews

Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access
24
Sep
2025

Salesforce CLI Installer Vulnerability Let Attackers Execute Code and Gain SYSTEM-Level Access

A critical vulnerability in the Salesforce CLI installer (sf-x64.exe) enables attackers to achieve arbitrary code execution, privilege escalation, and SYSTEM-level…

Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware
24
Sep
2025

Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware

In recent weeks, cybersecurity teams have observed a surge in malicious GitHub repositories masquerading as legitimate security and financial software….

New North Korean IT Worker With Innocent Job Application Get Access to Organization’s Network
24
Sep
2025

New North Korean IT Worker With Innocent Job Application Get Access to Organization’s Network

In recent months, a sophisticated threat actor leveraging North Korean IT worker employment fraud has surfaced, demonstrating how social engineering…

Hackers Can Compromise Chromium Browsers in Windows by Loading Arbitrary Extensions
24
Sep
2025

Hackers Can Compromise Chromium Browsers in Windows by Loading Arbitrary Extensions

Chromium-based browsers, including Chrome, Edge, and Brave, manage installed extensions via JSON preference files stored under %AppData%GoogleUser DataDefaultPreferences (for domain-joined machines)…

UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports
24
Sep
2025

UK Police Arrested Man Linked to Ransomware Attack That Crippeled European Airports

A man in his forties has been arrested in West Sussex, England, in connection with a cyber-attack that has caused…

Hackers Can Bypass EDR by Downloading Malicious File as In-Memory PE Loader
24
Sep
2025

Hackers Can Bypass EDR by Downloading Malicious File as In-Memory PE Loader

A sophisticated technique that allows attackers to execute malicious code directly in memory is gaining traction, posing a significant challenge…

OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission
24
Sep
2025

OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission

A severe security vulnerability in OnePlus OxygenOS has been discovered that allows any installed application to read SMS and MMS…

Hackers Exploiting Libraesva Email Security Gateway Vulnerability to Inject Malicious Commands
24
Sep
2025

Hackers Exploiting Libraesva Email Security Gateway Vulnerability to Inject Malicious Commands

Libraesva has issued an emergency patch for a significant command injection vulnerability in its Email Security Gateway (ESG) after confirming…

ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack
24
Sep
2025

ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack

A sophisticated cybercrime campaign has emerged that transforms legitimate AWS infrastructure into weaponized attack platforms through an innovative combination of…

New YiBackdoor Allows Attackers to Execute Arbitrary Commands and Exfiltrate Sensitive Data from Hacked Systems
24
Sep
2025

New YiBackdoor Allows Attackers to Execute Arbitrary Commands and Exfiltrate Sensitive Data from Hacked Systems

A sophisticated new malware family dubbed YiBackdoor has emerged in the cybersecurity landscape, posing a significant threat to organizations worldwide….

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks
24
Sep
2025

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a high-severity zero-day vulnerability in Google Chrome…

CISA Warns of Shai-Hulud Self-Replicating Worm Compromised 500+ Packages in npm Registry
24
Sep
2025

CISA Warns of Shai-Hulud Self-Replicating Worm Compromised 500+ Packages in npm Registry

CISA has issued an urgent security Alert in response to a large-scale software supply chain attack on npmjs.com, the world’s…