How Russia’s Largest Private University is Linked to a $25M Essay Mill – Krebs on Security
06
Dec
2025

How Russia’s Largest Private University is Linked to a $25M Essay Mill – Krebs on Security

A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious connections…

Chinese State Hackers Use New BRICKSTORM Malware Against VMware Systems
06
Dec
2025

Chinese State Hackers Use New BRICKSTORM Malware Against VMware Systems – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More

Major security agencies from the US and Canada have issued a serious alert about BRICKSTORM, a new cybersecurity threat believed…

Security News This Week: Oh Crap, Kohler’s Toilet Cameras Aren’t Really End-to-End Encrypted
06
Dec
2025

Security News This Week: Oh Crap, Kohler’s Toilet Cameras Aren’t Really End-to-End Encrypted

An AI image creator startup left its database unsecured, exposing more than a million images and videos its users had…

Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation
06
Dec
2025

Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation

Dec 06, 2025Ravie LakshmananVulnerability / Patch Management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday formally added a…

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions
06
Dec
2025

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows…

FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads
06
Dec
2025

FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads

A newly discovered Android banking trojan, FvncBot, has emerged as a sophisticated threat targeting mobile banking users in Poland. Researchers…

2.15M Next.js Web Services Exposed Online, Active Attacks Reported
06
Dec
2025

2.15M Next.js Web Services Exposed Online, Active Attacks Reported

Security teams worldwide are rushing to patch systems after the disclosure of a critical React vulnerability, CVE-2025-55182, widely known as…

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now
06
Dec
2025

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web…

Beyond CVEs – Turning Visibility into Action with ASM
06
Dec
2025

Beyond CVEs – Turning Visibility into Action with ASM

Torrance, California, USA, December 5th, 2025, CyberNewsWire Criminal IP will host a live webinar on December 16 at 11:00 AM…

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing
06
Dec
2025

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Penetration Testing Index

Madison, United States, December 5th, 2025, CyberNewsWire Sprocket Security is proud to announce that it has once again been recognized…

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges
06
Dec
2025

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges

Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the…

Maximum-severity XXE vulnerability discovered in Apache Tika
06
Dec
2025

Maximum-severity XXE vulnerability discovered in Apache Tika

Maximum-severity XXE vulnerability discovered in Apache Tika Pierluigi Paganini December 06, 2025 A maximum severity vulnerability in Apache Tika, tracked…