Category: CyberSecurityNews

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege
11
Nov
2025

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated…

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access
11
Nov
2025

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any…

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub
11
Nov
2025

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub

A new security investigation reveals that 65% of prominent AI companies have leaked verified secrets on GitHub, exposing API keys,…

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses
11
Nov
2025

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses…

Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data
11
Nov
2025

Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight…

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature
11
Nov
2025

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster…

SAP Security Update - Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks
11
Nov
2025

SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones,…

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks
11
Nov
2025

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat…

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware
11
Nov
2025

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote…

Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO
10
Nov
2025

Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO

Cybercriminals are increasingly targeting websites to inject malicious links and boost their search engine optimization rankings through sophisticated blackhat SEO…

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case
10
Nov
2025

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case

Francesco Nicodemo, a prominent political communications strategist and former Democratic Party communications director, has been identified as a new target…

APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins
10
Nov
2025

APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins

The construction industry has emerged as a lucrative target for advanced persistent threat groups and organized cybercriminal networks seeking unauthorized…