Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to their scanning methodologies, …

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for financial fraud. This toolkit, observed by Varonis, allows threat actors, …

What’s Next for SOC in 2026: Get the Early-Adopter Advantage 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity is about to hit a turning point in 2026. Attackers aren’t only testing AI but also building campaigns around it. Their tooling is getting faster, more adaptive, and far better at …

Microsoft Outlook Vulnerability Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical remote code execution (RCE)vulnerability in Outlook that could allow attackers to execute malicious code on vulnerable systems. The flaw, tracked as CVE-2025-62562, was released on …

North Korean Hackers Exploit React2Shell Vulnerability in the Wild to Deploy EtherRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier. …

FortiSandbox OS command injection Vulnerability Let Attackers execute Malicious code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has released a critical security update for its FortiSandbox analysis appliances to fix a dangerous vulnerability. If left unpatched, this flaw could allow attackers to take control of the …

Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security update addressing a dangerous Windows PowerShell vulnerability that allows attackers to execute malicious code on affected systems. The vulnerability, tracked as CVE-2025-54100, was publicly disclosed on December 9, 2025, …

CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-priority warning regarding a critical security flaw in WinRAR, the popular file compression tool used by millions of Windows users. The vulnerability, tracked as CVE-2025-6218, is currently being exploited by …

Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability dubbed “GeminiJack” in Google Gemini Enterprise and previously Vertex AI Search that let attackers steal sensitive corporate data from Gmail, Calendar, and Docs with minimal effort. …