Category: CyberSecurityNews

Elastic Defend for Windows Vulnerability Let Attackers Escalate Privileges
10
Nov
2025

Elastic Defend for Windows Vulnerability Let Attackers Escalate Privileges

Elastic has disclosed a significant security vulnerability in Elastic Defend for Windows that could allow attackers to escalate their privileges…

MAD-CAT Meow Attack Tool to Simulate Real-World Data Corruption Attacks
10
Nov
2025

MAD-CAT Meow Attack Tool to Simulate Real-World Data Corruption Attacks

MAD-CAT (Meow Attack Data Corruption Automation Tool) targets MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, exactly the systems hit…

Monsta web-based FTP Remote Code Execution Vulnerability Exploited
10
Nov
2025

Monsta web-based FTP Remote Code Execution Vulnerability Exploited

A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises…

Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk
10
Nov
2025

Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk

Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms. These flaws could allow attackers…

AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engine's
10
Nov
2025

AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engine’s

HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need…

New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic
09
Nov
2025

New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic

A sophisticated side-channel attack that exposes the topics of conversations with AI chatbots, even when traffic is protected by end-to-end…

Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched
08
Nov
2025

Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security…

Google Maps Adds Feature for Businesses to Report Ransom Demands for Removing Bad Reviews
08
Nov
2025

Google Maps Adds Feature for Businesses to Report Ransom Demands for Removing Bad Reviews

Scammers are targeting businesses with a new extortion scheme, and Google Maps is fighting back with a dedicated reporting tool….

08
Nov
2025

Hackers Hijacking Samsung Galaxy Phones by Exploiting 0-Day Using a Single Image Via WhatsApp

A sophisticated spyware operation targeting Samsung Galaxy devices, dubbed LANDFALL, which exploited a zero-day vulnerability to infiltrate phones through seemingly…

Threat Actors Leveraging RDP Credentials to Deploy Cephalus Ransomware
08
Nov
2025

Threat Actors Leveraging RDP Credentials to Deploy Cephalus Ransomware

A newly identified ransomware group, Cephalus, has emerged as a significant threat to organizations worldwide, exploiting stolen Remote Desktop Protocol…

German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
08
Nov
2025

German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure

German hosting provider aurologic GmbH has emerged as a central facilitator within the global malicious infrastructure ecosystem, providing upstream transit…

ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process
07
Nov
2025

ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process

ClickFix attacks have experienced a dramatic surge over the past year, establishing themselves as a cornerstone of modern social engineering…