Category: CyberSecurityNews

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack
11
Dec
2025

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

Critical security patches on December 10, 2025, addressing ten significant vulnerabilities across its Community Edition and Enterprise Edition platforms. GitLab…

ValleyRAT Malware Uses Stealthy Driver Install to Bypass Windows 11 Protections
11
Dec
2025

ValleyRAT Malware Uses Stealthy Driver Install to Bypass Windows 11 Protections

ValleyRAT, also known as Winos or Winos4.0, has emerged as one of the most sophisticated backdoors targeting organizations worldwide. This…

2 Chinese Hackers Trained Cisco Program Now Attacking Cisco Devices
11
Dec
2025

2 Chinese Hackers Trained Cisco Program Now Attacking Cisco Devices

The cybersecurity world faces an ironic threat as two Chinese hackers who once excelled in Cisco’s training program are now…

Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer
11
Dec
2025

Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer

A new AMOS InfoStealer campaign is abusing trust in ChatGPT to infect Mac devices under the guise of simple troubleshooting…

Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File
11
Dec
2025

Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File

Security researchers have uncovered a significant threat targeting developers through the VS Code Marketplace. A coordinated campaign involving 19 malicious…

Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild
11
Dec
2025

Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild

Google has released an urgent security update for the Chrome browser to address a high-severity zero-day vulnerability that is currently…

Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data
11
Dec
2025

Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory…

Adobe Acrobat Reader Vulnerabilities let Attackers Execute Arbitrary Code and Bypass Security
11
Dec
2025

Adobe Acrobat Reader Vulnerabilities let Attackers Execute Arbitrary Code and Bypass Security

Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code and bypass…

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS
10
Dec
2025

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers…

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
10
Dec
2025

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting…

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks
10
Dec
2025

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks

A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for…

What’s Next for SOC in 2026: Get the Early-Adopter Advantage 
10
Dec
2025

What’s Next for SOC in 2026: Get the Early-Adopter Advantage 

Cybersecurity is about to hit a turning point in 2026. Attackers aren’t only testing AI but also building campaigns around…