LANSCOPE Endpoint Manager Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Motex has disclosed a severe remote code execution vulnerability in its LANSCOPE Endpoint Manager On-Premise Edition. Assigned CVE-2025-61932, the flaw carries a CVSS 3.0 score of 9.8, classifying it as an emergency-level threat. This vulnerability could allow attackers to execute …

131 Malicious Extensions Targeting WhatsApp Used Found in Chrome Web Store

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past several months, cybersecurity researchers have observed a surge of fraudulent Chrome extensions masquerading as legitimate WhatsApp Web automation tools. These 131 rebranded clones, each presenting as distinct offerings, share an identical codebase designed to automate bulk messaging …

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Zyxel’s ATP and USG series firewalls that allows attackers to bypass authorization controls and access sensitive system configurations. Dubbed CVE-2025-9133, this flaw affects devices running firmware versions up to V5.40(ABPS.0) and enables unauthorized viewing and downloading …

Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has disclosed a serious security flaw in ASP.NET Core that enables authenticated attackers to smuggle HTTP requests and evade critical protections. Tracked as CVE-2025-55315, the vulnerability stems from inconsistent handling of HTTP requests, a classic issue known as HTTP …

AWS Declares Major Outage Resolved After Nearly 24 Hours of Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS), the world’s largest cloud computing provider, has officially marked a widespread outage in its US-EAST-1 region as resolved, following nearly a full day of cascading failures that disrupted services for millions worldwide. The incident, which began …

Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with attackers deploying over 30,000 new IP addresses daily to exploit timing-based vulnerabilities. This coordinated effort, linked to a global botnet, has seen unique IPs surge past 500,000 since September …

Automatic BitLocker Encryption May Silently Lock Away Your Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Reddit poster detailed how reinstalling Windows 11 unexpectedly encrypted two of their backup drives with BitLocker, locking away 3TB of irreplaceable data without any prior setup. The incident, shared onReddit, highlights the risks of Microsoft’s automatic encryption feature in …

CISA Warns of Windows SMB Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on October 20, 2025, highlighting a severe vulnerability CVE-2025-33073 in Microsoft’s Windows SMB Client. Dubbed an improper access control flaw, this vulnerability tracked under CVE details yet to be …

71,000+ WatchGuard Devices Vulnerable to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has uncovered more than 71,000 internet-exposed WatchGuard devices running vulnerable versions of Fireware OS. The flaw, tracked as CVE-2025-9242, stems from an out-of-bounds write vulnerability in the IKEv2 implementation, potentially allowing remote attackers to execute arbitrary code …

Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software has been disclosed, allowing attackers to execute malicious code remotely via seemingly innocuous audio messages. Google Project Zero’s Ivan Fratric and Natalie Silvanovich have identified an out-of-bounds write …