AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More – Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widespread Amazon Web Services (AWS) outage on Monday disrupted operations for millions of users worldwide, knocking out access to everything from streaming giants to social media platforms and financial apps. The incident, which began early in the morning, affected …

Canva Down – Suffers Global Outage, Leaving Millions of Users Unable to Access Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Canva, the popular graphic design platform, is reeling from a widespread outage that has rendered its services inaccessible to millions of users worldwide. As of 19:16 AEDT (02:46 IST), the platform’s status page reports “significantly increased error rates” impacting nearly …

PoC Exploit Released for Windows Server Update Services Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Microsoft’s Windows Server Update Services (WSUS), enabling unauthenticated attackers to execute remote code with SYSTEM privileges on affected servers. Dubbed CVE-2025-59287 and assigned a CVSS v3.1 score of …

New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files into antivirus executable folders, potentially enabling malware persistence and evasion. Developed by cybersecurity expert Two Seven One Three, the tool demonstrates a novel technique …

PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability in the Pluggable Authentication Modules (PAM) framework was assigned the identifier CVE-2025-8941. This vulnerability stems from the heart of Linux operating systems, enabling attackers with local access to exploit symlink attacks and race conditions for full root …

WatchGuard VPN Vulnerability Let Remote Attacker Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WatchGuard has disclosed a critical out-of-bounds write vulnerability in its Fireware OS, enabling remote unauthenticated attackers to execute arbitrary code via IKEv2 VPN connections. Designated CVE-2025-9242 under advisory WGSA-2025-00015, the flaw carries a CVSS 4.0 score of 9.3, highlighting its …

Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Volkswagen Group has issued a statement addressing claims by the ransomware group 8Base, which alleges it has stolen and leaked sensitive data from the automaker. The German carmaker maintains that its core IT infrastructure remains unaffected; however, the company’s vague …

Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s latest security update has rendered USB keyboards and mice inoperable within the Windows Recovery Environment (WinRE). Released on October 14, 2025, as KB5066835 for OS Build 26100.6899, the patch affects Windows 11 versions 24H2 and 25H2, as well as …

American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite (EBS). The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing …

New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging Microsoft Azure Blob Storage to craft highly convincing phishing sites that mimic legitimate Office 365 login portals, putting Microsoft 365 users at severe risk of credential theft. This method exploits trusted Microsoft infrastructure, making the attacks …