Category: CyberSecurityNews

Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users
08
Dec
2025

Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users

A commercial spyware company called Intellexa has exploited 15 zero-day vulnerabilities since 2021 to target iOS and Android users worldwide….

Critical React2Shell RCE Vulnerability Exploitied in the Wild to Execute Malicious Code
08
Dec
2025

Critical React2Shell RCE Vulnerability Exploitied in the Wild to Execute Malicious Code

A critical remote code execution vulnerability, tracked as CVE-2025-55182 and dubbed “React2Shell,” is now under active exploitation in the wild….

NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools
08
Dec
2025

NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools

A unified offensive security toolkit, NETREAPER, developed by OFFTRACKMEDIA Studios, consolidates over 70 penetration testing tools into a single, user-friendly…

LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak
07
Dec
2025

LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak

LockBit 5.0 key infrastructure exposed, revealing the IP address 205.185.116.233, and the domain karma0.xyz is hosting the ransomware group’s latest…

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs
07
Dec
2025

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

In an escalating campaign targeting remote access infrastructure, threat actors have initiated active exploitation attempts against Palo Alto Networks’ GlobalProtect…

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads
06
Dec
2025

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

A dangerous new Android banking malware named FvncBot was first observed on November 25, 2025. This malicious tool is designed to steal…

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions
06
Dec
2025

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows…

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now
06
Dec
2025

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web…

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges
06
Dec
2025

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges

Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the…

Russian Hackers Spoof European Events in Targeted Phishing Attacks
05
Dec
2025

Russian Hackers Spoof European Events in Targeted Phishing Attacks

Russian threat actors are running a new wave of phishing campaigns that spoof major European security events to quietly steal…

AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2
05
Dec
2025

AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2

A persistent privilege escalation technique in AWS that allows attackers with limited permissions to execute code under higher-privileged execution roles…

Cloudflare Outage Traced to Emergency React2Shell Patch Deployment
05
Dec
2025

Cloudflare Outage Traced to Emergency React2Shell Patch Deployment

Cloudflare’s global network suffered a brief but widespread disruption this morning, lasting approximately 25 minutes, due to an internal change…