FortiOS CLI Command Bypass Vulnerability Let Attacker Execute System Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet disclosed a high-severity vulnerability in its FortiOS operating system on October 14, 2025, that could enable local authenticated attackers to execute arbitrary system commands. Tracked as CVE-2025-58325, the flaw stems from an incorrect provision of specified functionality (CWE-684) in …

Microsoft October 2025 Patch Tuesday – 4 Zero-days and 172 Vulnerabilities Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft rolled out its October 2025 Patch Tuesday updates, addressing a staggering 172 vulnerabilities across its ecosystem, including four zero-day flaws, of which two are actively exploited in the wild. This monthly security bulletin underscores the relentless pace of threat …

Support for Windows 10 Ends Today Leaving Users Vulnerable to Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft officially ended support for Windows 10, marking the close of a decade-long era for one of the most popular operating systems in history. This means that as of today, the company will no longer deliver free security updates, feature …

Hackers Mimic as OpenAI and Sora Services to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, a sophisticated phishing campaign has emerged, targeting corporate and consumer accounts by impersonating both OpenAI and Sora-branded login portals. Attackers distribute emails crafted to appear as legitimate service notifications, warning recipients of account suspension or unusual activity. …

UEFI Shell Vulnerabilities Could Let Hackers Bypass Secure Boot on 200,000+ Laptops

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers can exploit vulnerabilities in signed UEFI shells to bypass Secure Boot protections on over 200,000 Framework laptops and desktops. According to Eclypsium, these vulnerabilities expose fundamental flaws in how modern systems trust boot components, potentially enabling persistent malware infections …

Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, United States, October 14th, 2025, CyberNewsWire Criminal IP at Booth J30 | Sands Expo Singapore | October 21 – 23, 2025 Criminal IP, a global cybersecurity company, announced its participation in GovWare 2025, Asia’s largest cybersecurity conference, which will …

Sweet Security Named Cloud Security Leader and CADR Leader in Latio Cloud Security Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tel Aviv, Israel, October 14th, 2025, CyberNewsWire Sweet Security, a leader in Runtime Cloud and AI security solutions, today announced that it has been recognized as both a Cloud Security Leader and a Cloud Application Detection & Response (CADR) Leader …

New Pixnapping Attack Steals 2FA Codes From Google Authenticator Within 30 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pixnapping, a novel class of side-channel attacks targeting Android devices that can covertly extract sensitive screen data, including two-factor authentication (2FA) codes from Google Authenticator in under 30 seconds. This exploit leverages Android’s core APIs and a hardware vulnerability in …

Thousands of North Korean IT Workers Using VPNs and ‘Laptop Farms’ to Bypass Origin Verification

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since at least 2018, a covert network of thousands of North Korean IT contractors has infiltrated global technology and infrastructure firms by masquerading as legitimate freelancers. These operatives, operating under fabricated identities with AI-generated headshots, routinely use VPN services and …

Kaspersky Details Windows 11 Forensic Artifacts and Changes With Windows 10 for Investigators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As Microsoft pulls the plug on Windows 10 support today, October 14, 2025, organizations worldwide face a pivotal shift toward Windows 11. Yet adoption has lagged, with Kaspersky’s Global Emergency Response Team (GERT) noting in early 2025 that the decade-old …