Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions
06
Dec
2025

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows…

FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads
06
Dec
2025

FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads

A newly discovered Android banking trojan, FvncBot, has emerged as a sophisticated threat targeting mobile banking users in Poland. Researchers…

2.15M Next.js Web Services Exposed Online, Active Attacks Reported
06
Dec
2025

2.15M Next.js Web Services Exposed Online, Active Attacks Reported

Security teams worldwide are rushing to patch systems after the disclosure of a critical React vulnerability, CVE-2025-55182, widely known as…

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now
06
Dec
2025

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web…

Beyond CVEs – Turning Visibility into Action with ASM
06
Dec
2025

Beyond CVEs – Turning Visibility into Action with ASM

Torrance, California, USA, December 5th, 2025, CyberNewsWire Criminal IP will host a live webinar on December 16 at 11:00 AM…

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing
06
Dec
2025

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Penetration Testing Index

Madison, United States, December 5th, 2025, CyberNewsWire Sprocket Security is proud to announce that it has once again been recognized…

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges
06
Dec
2025

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges

Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the…

Maximum-severity XXE vulnerability discovered in Apache Tika
06
Dec
2025

Maximum-severity XXE vulnerability discovered in Apache Tika

Maximum-severity XXE vulnerability discovered in Apache Tika Pierluigi Paganini December 06, 2025 A maximum severity vulnerability in Apache Tika, tracked…

Critical vulnerability in Fortinet FortiWeb is under exploitation
06
Dec
2025

State-linked groups target critical vulnerability in React Server Components

Researchers warn that critical vulnerabilities in Meta’s React Server Components and Next.js are under threat from botnets and state-linked adversaries. …

Attackers hit React defect as researchers quibble over proof
06
Dec
2025

Attackers hit React defect as researchers quibble over proof

Attackers of different origins and motivations swiftly exploited a critical vulnerability dubbed React2Shell, affecting React Server Components shortly after Meta…

More evidence your AI agents can be turned against you
05
Dec
2025

More evidence your AI agents can be turned against you

Agentic AI tools are being pushed into software development pipelines, IT networks and other business workflows. But using these tools…

Russian Hackers Spoof European Events in Targeted Phishing Attacks
05
Dec
2025

Russian Hackers Spoof European Events in Targeted Phishing Attacks

Russian threat actors are running a new wave of phishing campaigns that spoof major European security events to quietly steal…