Category: CyberSecurityNews

Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet
28
Aug
2025

Kea DHCP Server Vulnerability Let Remote Attacker With a Single Crafted Packet

A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure…

Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Tactics
28
Aug
2025

Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Tactics

Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated…

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks
28
Aug
2025

CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks

CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775.  This memory…

New Malware Attack Exploiting TASPEN's Legacy to Target Indonesian Senior Citizens
28
Aug
2025

New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens

A sophisticated malware campaign has emerged, targeting Indonesia’s most vulnerable digital citizens through a calculated exploitation of trust in the…

Underground Ransomware Gang With New Tactics Against Organizations Worldwide
28
Aug
2025

Underground Ransomware Gang With New Tactics Against Organizations Worldwide

Over the past year, the Underground ransomware gang has emerged as a formidable threat to organizations across diverse industries and…

Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents
28
Aug
2025

Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents

A widespread service issue is impacting Microsoft Teams users globally this Thursday, preventing many from opening embedded Microsoft Office documents…

New ShadowCaptcha Attack Exploiting Hundreds of WordPress Sites to Tricks Victims into Executing Malicious Commands
28
Aug
2025

New ShadowCaptcha Attack Exploiting Hundreds of WordPress Sites to Tricks Victims into Executing Malicious Commands

A sophisticated global cybercrime campaign dubbed “ShadowCaptcha” has emerged as a significant threat to organizations worldwide, leveraging fake Google and…

Attacker Context and Historical iOS Zero-Click Similarities
28
Aug
2025

Attacker Context and Historical iOS Zero-Click Similarities

Apple has issued emergency security updates across its entire ecosystem to address CVE-2025-43300, a critical zero-day vulnerability in the ImageIO framework that…

NVIDIA NeMo AI Curator Enables Code Execution and Privilege Escalation
27
Aug
2025

NVIDIA NeMo AI Curator Enables Code Execution and Privilege Escalation

NVIDIA has issued a critical security bulletin addressing a high-severity vulnerability in its NeMo Curator platform that could allow attackers…

How ClickFix and Multi-Stage Frameworks Are Breaking Enterprise Defenses
27
Aug
2025

How ClickFix and Multi-Stage Frameworks Are Breaking Enterprise Defenses

August 2025 has marked a significant evolution in cybercrime tactics, with threat actors deploying increasingly sophisticated phishing frameworks and social…

28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild
27
Aug
2025

28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild

A critical zero-day remote code execution (RCE) vulnerability, tracked as CVE-2025-7775, is affecting over 28,000 Citrix instances worldwide. The flaw…

PoC Exploit Released for CrushFTP 0-day Vulnerability (CVE-2025-54309)
27
Aug
2025

PoC Exploit Released for CrushFTP 0-day Vulnerability (CVE-2025-54309)

A weaponized proof-of-concept exploit has been publicly released targeting CVE-2025-54309, a severe authentication bypass vulnerability affecting CrushFTP file transfer servers. …