Category: CyberSecurityNews

GitLab Security Update - Patch for Multiple Vulnerabilities in Community and Enterprise Edition
24
Jul
2025

GitLab Security Update – Patch for Multiple Vulnerabilities in Community and Enterprise Edition

GitLab has released critical security patches addressing multiple vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with…

First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology
24
Jul
2025

First Known LLM-Powered Malware From APT28 Hackers Integrates AI Capabilities into Attack Methodology

The newly revealed LAMEHUG campaign signals a watershed moment for cyber-def: Russian state-aligned APT28 has fused a large language model…

SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups
24
Jul
2025

SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups

A critical zero-day vulnerability in Microsoft SharePoint servers has become a playground for threat actors across the cybercriminal spectrum, with…

TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands
24
Jul
2025

TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands

Two high-severity vulnerabilities in TP-Link VIGI network video recorder (NVR) systems could allow attackers to execute arbitrary commands on affected…

Chinese Hackers Attacking Windows Systems in Targeted Campaign to Deploy Ghost RAT and PhantomNet Malwares
24
Jul
2025

Chinese Hackers Attacking Windows Systems in Targeted Campaign to Deploy Ghost RAT and PhantomNet Malwares

Threat researchers are warning of twin Chinese-nexus espionage operations—“Operation Chat” and “Operation PhantomPrayers”—that erupted in the weeks preceding the Dalai…

Metasploit Module Released For Actively Exploited SharePoint 0-Day Vulnerabilities
24
Jul
2025

Metasploit Module Released For Actively Exploited SharePoint 0-Day Vulnerabilities

Researchers have developed a new Metasploit exploit module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server that are being actively…

Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware
24
Jul
2025

Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware

Cybersecurity researchers have uncovered a sophisticated malware campaign where threat actors are exploiting Hangul Word Processor (.hwp) documents to distribute…

New AI-Powered Wi-Fi Biometrics WhoFi Tracks Humans Behind Walls with 95.5% Accuracy
24
Jul
2025

New AI-Powered Wi-Fi Biometrics WhoFi Tracks Humans Behind Walls with 95.5% Accuracy

WhoFi surfaced last on the public repository ArXiv, stunning security teams with a proof-of-concept that turns ordinary 2.4 GHz routers…

NoName057(16)'s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months
24
Jul
2025

NoName057(16)’s Hackers Attacked 3,700 Unique Devices Over Last Thirteen Months

The pro-Russian hacktivist group NoName057(16) has orchestrated a massive distributed denial-of-service campaign targeting over 3,700 unique hosts across thirteen months,…

Splunk Details on How to Detect, Mitigate and Respond to CitrixBleed 2 Attack
24
Jul
2025

Splunk Details on How to Detect, Mitigate and Respond to CitrixBleed 2 Attack

CitrixBleed 2 (CVE-2025-5777) erupted in 2025 when researchers uncovered an out-of-bounds read in Citrix NetScaler ADC and Gateway that lets…

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks
24
Jul
2025

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks

CISA has issued an urgent warning about a critical vulnerability in Google Chromium that threat actors are actively exploiting.  The…

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset 'root' Passwords
24
Jul
2025

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset ‘root’ Passwords

UNC3944, a financially driven threat organization associated with “0ktapus,” “Octo Tempest,” and “Scattered Spider,” launched a sophisticated cyber campaign that…