Category: CyberSecurityNews

FortiWeb Authentication Bypass Vulnerability Exploited
14
Nov
2025

FortiWeb Authentication Bypass Vulnerability Exploited

Threat actors are actively exploiting a critical authentication bypass vulnerability in Fortinet’s FortiWeb web application firewall (WAF) worldwide, prompting defenders…

Google Sues 'Lighthouse' Phishing-as-a-service Kit Behind Massive Phishing Attacks
13
Nov
2025

Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks

Google security researchers recently uncovered a sophisticated criminal operation called “Lighthouse” that has victimized over one million people across more…

Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program
13
Nov
2025

Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program

Cybercriminals are now exploiting remote monitoring and management tools to spread dangerous malware while avoiding detection by security systems. The…

New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs 
13
Nov
2025

New Wave of Steganography Attacks: Hackers Hiding XWorm in PNGs 

ANY.RUN experts recently uncovered a new XWorm campaign that uses steganography to conceal malicious payloads inside seemingly harmless PNG images. What appears to…

Operation Endgame - 1,000+ Servers Used by Rhadamanthys, VenomRAT, and Elysium Dismantled
13
Nov
2025

Operation Endgame – 1,000+ Servers Used by Rhadamanthys, VenomRAT, and Elysium Dismantled

Law enforcement agencies disrupted a vast network of cybercrime tools between November 10 and 14, 2025, coordinated from Europol’s headquarters…

Palo Alto PAN-OS Firewall Vulnerability Let Attackers Reboot Firewall by Sending Malicious Packet
13
Nov
2025

Palo Alto PAN-OS Firewall Vulnerability Let Attackers Reboot Firewall by Sending Malicious Packet

Palo Alto Networks has disclosed a critical denial-of-service vulnerability in its PAN-OS firewall software that allows unauthenticated attackers to remotely…

Microsoft Defender for O365 New Feature Allows Security Teams to Trigger Automated Investigations
13
Nov
2025

Microsoft Defender for O365 New Feature Allows Security Teams to Trigger Automated Investigations

Microsoft has rolled out enhanced remediation capabilities in Defender for Office 365 (O365), enabling security teams to initiate automated investigations…

MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender
13
Nov
2025

MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender

A newly documented malware campaign demonstrates how attackers are leveraging Windows LNK shortcuts to deliver the MastaStealer infostealer. The attack…

Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting
13
Nov
2025

Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting

Microsoft has launched a new security feature in Teams Premium called “Prevent screen capture,” designed to block screenshots and recordings…

NHS Investigating Oracle EBS Hack Following Cl0p Ransomware Group Claim
13
Nov
2025

NHS Investigating Oracle EBS Hack Following Cl0p Ransomware Group Claim

The notorious Cl0p ransomware group has claimed responsibility for breaching the UK’s National Health Service (NHS), spotlighting vulnerabilities in Oracle’s…

Multiple Kibana Vulnerabilities Enables SSRF and XSS Attacks
13
Nov
2025

Multiple Kibana Vulnerabilities Enables SSRF and XSS Attacks

Elastic Security has disclosed critical vulnerabilities affecting Kibana that could enable attackers to execute Server-Side Request Forgery (SSRF) and Cross-Site…

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data
13
Nov
2025

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data

GitLab has released urgent security patches addressing multiple vulnerabilities affecting both the Community Edition and the Enterprise Edition. The company…