Windows Rust-based Kernel GDI Vulnerability Leads to Crash and Blue Screen of Death Error

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability in Microsoft’s newly implemented Rust-based kernel component for the Graphics Device Interface (GDI) in Windows. This flaw, which could trigger a system-wide crash via a Blue Screen of Death (BSOD), highlights the challenges of integrating memory-safe languages into …

APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russia’s APT28 has resurfaced in mid-2025 with a sophisticated spear-phishing campaign that weaponizes Office documents to deploy two novel payloads: BeardShell, a C-based backdoor leveraging IceDrive as a command-and-control channel, and Covenant’s HTTP Grunt Stager, which communicates via the Koofr …

Critical ConnectWise Vulnerabilities Allow Attackers To Inject Malicious Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ConnectWise released a critical security update for its Automate platform on October 16, 2025. The patch, version 2025.9, addresses serious flaws in agent communications that could let attackers intercept sensitive data or push malicious software updates. These vulnerabilities primarily affect …

Email Bombs Exploit Lax Authentication in Zendesk

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers simultaneously. Zendesk is an automated help desk service designed to …

LinkPro Rootkit Attacking GNU/Linux Systems Using eBPF Module to Hide Malicious Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated rootkit targeting GNU/Linux systems has emerged, leveraging advanced eBPF (extended Berkeley Packet Filter) technology to conceal malicious activities and evade traditional monitoring tools. The threat, known as LinkPro, was discovered during a digital forensic investigation of a compromised …

Cisco Desk, IP, and Video Phone Vulnerabilities Let Remote Attackers Trigger DoS And XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a security advisory warning of multiple vulnerabilities in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 models running Cisco Session Initiation Protocol (SIP) Software. Published on October 15, 2025, the …

VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has launched Workstation 25H2 and Fusion 25H2, the newest iterations of its desktop hypervisors, featuring a revamped versioning system, enhanced tools, and broader compatibility with modern hardware and operating systems. These updates aim to streamline virtualization for developers, IT …

North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, a sophisticated malware campaign—dubbed EtherHiding—has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide. The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, …

Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 269,000 F5 devices are reportedly exposed to the public internet daily, according to data from The Shadowserver Foundation. This exposure comes at a critical time following F5’s disclosure of a sophisticated nation-state attack that compromised its development environment, stealing …

F5 Released Security Updates Covering Multiple Products Following Recent Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

F5 Networks, a leading provider of application security and delivery solutions, has disclosed a significant security breach involving a nation-state threat actor, prompting the release of critical updates for its core products. Detected in August 2025, the incident exposed internal …