Category: CyberSecurityNews

Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks
01
Apr
2025

Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks

Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085 that have been actively…

CrushFTP Vulnerability Exploited in Attacks Following PoC Release
01
Apr
2025

CrushFTP Vulnerability Exploited in Attacks Following PoC Release

Security researchers have confirmed active exploitation attempts targeting the critical authentication bypass vulnerability in CrushFTP (CVE-2025-2825) following the public release…

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks
01
Apr
2025

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks

Researchers have detected an alarming surge in malicious scanning activity targeting Palo Alto Networks’ GlobalProtect VPN portals.  Over a 30-day…

An Advanced Stealer Malware Selling Via Telegram To Steal Data From Windows
01
Apr
2025

An Advanced Stealer Malware Selling Via Telegram To Steal Data From Windows

DarkCloud is a sophisticated stealer malware that emerged in 2022, quickly positioning itself as one of the most prevalent threats…

ClickFake Interview - Lazarus Hackers Exploit Windows & macOS Users Fake Job Campaign
01
Apr
2025

ClickFake Interview – Lazarus Hackers Exploit Windows & macOS Users Fake Job Campaign

The Lazarus Group, a North Korean state-sponsored hacking collective, has launched a new campaign dubbed ClickFake Interview, targeting job seekers…

Earth Alux Hackers Employ VARGIET Malware to Attack Organizations
31
Mar
2025

Earth Alux Hackers Employ VARGIET Malware to Attack Organizations

The cybersecurity landscape has been disrupted by Earth Alux, a China-linked advanced persistent threat (APT) group actively conducting espionage operations…

Hewlett Packard RCE Vulnerability Allows Attackers to Bypass Authentication and Execute Remote Commands
31
Mar
2025

Hewlett Packard RCE Vulnerability Allows Attackers to Bypass Authentication and Execute Remote Commands

A critical unauthenticated remote code execution vulnerability (CVE-2024-13804) has been discovered in HPE Insight Cluster Management Utility (CMU) v8.2, enabling…

New Ubuntu Security Bypasses Allow Attackers to Exploit Kernel Vulnerabilities
31
Mar
2025

New Ubuntu Security Bypasses Allow Attackers to Exploit Kernel Vulnerabilities

Three critical bypasses in Ubuntu Linux’s unprivileged user namespace restrictions allow local attackers to escalate privileges and exploit kernel vulnerabilities. …

Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups
31
Mar
2025

Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups

The cybersecurity landscape is witnessing a growing complexity in the attribution of Advanced Persistent Threat (APT) actors, particularly the North…

Multiple Dell Unity Vulnerabilities Let Attackers Compromise Affected System
31
Mar
2025

Multiple Dell Unity Vulnerabilities Let Attackers Compromise Affected System

Dell Technologies has released a critical security update addressing multiple severe vulnerabilities in its Unity enterprise storage systems that could…

CrushFTP Vulnerability Exploited to Bypass Authentication
31
Mar
2025

CrushFTP Vulnerability Exploited to Bypass Authentication

A critical vulnerability (CVE-2025-2825) in CrushFTP, a widely used enterprise file transfer solution, allows attackers to bypass authentication and gain…

Cannon Printer Vulnerability Let Attackers Execute Arbitrary Code
31
Mar
2025

Cannon Printer Vulnerability Let Attackers Execute Arbitrary Code

Canon has issued a critical security advisory regarding a severe vulnerability detected in several of its printer drivers that could…