Category: CyberSecurityNews

Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack
25
Nov
2025

Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle…

Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely
25
Nov
2025

Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security…

HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials
25
Nov
2025

HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and…

ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen
25
Nov
2025

ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen

A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly…

NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes
25
Nov
2025

NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes

NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GR00T robotics platform. The vulnerabilities, tracked as CVE-2025-33183 and CVE-2025-33184,…

Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details
24
Nov
2025

Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details

A dangerous malware campaign has surfaced targeting cryptocurrency users through a deceptive Python package hosted on the PyPI repository. The…

LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuels the Development of Fully Autonomous Malware
24
Nov
2025

LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuels the Development of Fully Autonomous Malware

Large language models like GPT-3.5-Turbo and GPT-4 are transforming how we work, but they are also opening doors for cybercriminals…

Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
24
Nov
2025

Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention

Tel Aviv, Israel, November 24th, 2025, CyberNewsWire Blast is introducing a new operating model for cloud security with a first-of-its-kind…

Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
24
Nov
2025

Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details

A new malware campaign targeting Brazilian users has emerged, using WhatsApp as its primary distribution channel to spread banking trojans…

PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
24
Nov
2025

PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

A proof-of-concept exploit has been publicly released for CVE-2025-9501, a critical, unauthenticated command-injection vulnerability affecting W3 Total Cache, one of…

800+ npm Packages and Thousands of GitHub Repos Compromised
24
Nov
2025

800+ npm Packages and Thousands of GitHub Repos Compromised

A massive resurgence of the Sha1-Hulud supply chain malware has struck the open-source ecosystem, compromising over 800 npm packages and…

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper
24
Nov
2025

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper

India-aligned threat group Dropping Elephant has launched a sophisticated multi-stage cyberattack targeting Pakistan’s defense sector using a Python-based remote access…