Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild – 3 in 5 Stores Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have begun actively targeting a critical remote code execution flaw in Adobe’s Magento e-commerce platform, putting thousands of online stores at immediate risk just six weeks after Adobe issued an emergency patch. Known as SessionReaper and tracked as CVE-2025-54236, …

CISA Warns of Motex LANSCOPE Endpoint Manager Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical alert regarding a severe vulnerability in Motex LANSCOPE Endpoint Manager, a popular tool for managing IT assets across networks. Dubbed an improper verification of the source of a communication channel flaw, this issue allows attackers …

Jira Software Vulnerability Let Attacker Modify Any Filesystem Path Writable By JVM process

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has disclosed a high-severity path traversal vulnerability in Jira Software Data Center and Server that enables authenticated attackers to arbitrarily write files to any path accessible by the Java Virtual Machine (JVM) process. This flaw, tracked as CVE-2025-22167 with …

Impacket Tool in Kali Repo Upgraded With New Attack Paths and Relay Tricks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular Impacket toolkit, a staple in penetration testing and now integrated into the Kali Linux repository, is set for a major upgrade. Maintained by Fortra’s cybersecurity team, the forthcoming release, building on version 0.12, addresses long-standing community requests with …

DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Department of Homeland Security (DHS) has issued the first known federal search warrant compelling OpenAI to disclose user data tied to ChatGPT prompts. The warrant, unsealed last week in Maine and reviewed by cybersecurity outlets, stems from a year-long …

TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the async-tar Rust library and its popular forks, including the widely used tokio-tar. Dubbed TARmageddon and tracked as CVE-2025-62518, the bug carries a CVSS score of 8.1, classifying it as high severity. It allows attackers to …

Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has disclosed multiple critical vulnerabilities in its Oracle VM VirtualBox virtualization software, potentially allowing attackers to achieve complete control over the VirtualBox environment. These flaws, detailed in the October 2025 Critical Patch Update (CPU), affect the Core component of …

Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial Of Service Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9 on October 22, 2025, potentially allowing remote attackers to conduct cache poisoning attacks or cause denial-of-service (DoS) conditions on affected DNS resolvers. These flaws, tracked as CVE-2025-8677, CVE-2025-40778, …

Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments. These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically …

Critical Vulnerability in MCP Server Platform Exposes 3,000+ Servers and Thousands of API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Smithery.ai, a popular registry for Model Context Protocol (MCP) servers. This issue could have allowed attackers to steal from over 3,000 AI servers and take API keys from thousands of users across many services. MCP powers …