Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has urgently released patch versions 18.5.1, 18.4.3, and 18.3.5 for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security flaws, including several high-severity denial-of-service (DoS) vulnerabilities. These updates fix issues allowing specially crafted payloads to …

Decoding Microsoft 365 Audit Log Events Using Bitfield Mapping Technique – Investigation Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

When users authenticate to Microsoft cloud services, their activities generate authentication events recorded across multiple logging systems. Microsoft Entra sign-in logs and Microsoft 365 audit logs capture identical authentication events but represent this critical security data using different formats. Security …

Chinese Hackers Using ToolShell Vulnerability To Compromise Networks Of Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China-based threat actors have exploited the critical ToolShell vulnerability in Microsoft SharePoint servers to infiltrate networks across multiple continents, targeting government agencies and critical infrastructure in a suspected espionage campaign. This vulnerability, identified as CVE-2025-53770, enables unauthenticated remote code execution …

Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access To Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has disclosed two critical vulnerabilities in its E-Business Suite’s Marketing product that could hand full control to remote attackers. Dubbed CVE-2025-53072 and CVE-2025-62481, these flaws affect the Marketing Administration component and carry a perfect storm CVSS score of 9.8, …

Azure Apps Vulnerability Lets Hackers Create Malicious Apps Mimicking Microsoft Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security flaws in Microsoft’s Azure ecosystem enable cybercriminals to create deceptive applications that imitate official services like the “Azure Portal. Varonis found that Azure’s safeguards, designed to block reserved names for cross-tenant apps, could be bypassed using invisible Unicode characters. …

Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Monolock ransomware has surfaced in underground forums, with threat actors advertising version 1.0 for sale alongside stolen corporate credentials. First detected in late September, the malware exploits phishing emails containing malicious Word documents. Upon opening, the embedded macro downloads the …

New GlassWorm Using Invisible Code Hits Attacking VS Code Extensions on OpenVSX Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past week, cybersecurity professionals have been gripped by the emergence of GlassWorm, a highly sophisticated, self-propagating malware campaign targeting VS Code extensions on the OpenVSX Marketplace. The scale and technical complexity of this attack signal a turning point …

Hackers Exploited 34 Zero-Day Vulnerabilities And Earned $522,500 In Pwn2Own Ireland 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first day of Pwn2Own Ireland 2025 wrapped up with a bang, as security researchers uncovered 34 unique zero-day vulnerabilities across various smart devices. Not a single attempt failed, leading to a total payout of $522,500 in prizes. This event, …

Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors infiltrated the official Xubuntu website, redirecting torrent downloads to a malicious ZIP file containing Windows-targeted malware. The incident, uncovered on October 18, 2025, highlights vulnerabilities in community-maintained Linux distribution sites amid rising interest in alternatives to end-of-life operating …

Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has swiftly addressed a high-severity flaw in its Chrome browser’s V8 JavaScript engine, releasing an emergency update to thwart potential remote code execution attacks. The vulnerability, tracked as CVE-2025-12036, stems from an inappropriate implementation within V8, the open-source JavaScript …