PoC Exploit Released For Nothing Phone Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in the secure boot chain of the Nothing Phone (2a) and CMF Phone 1, potentially affecting other devices using MediaTek systems-on-a-chip (SoCs). The exploit, named Fenrir and published by …

77% of Employees Share Company Secrets on ChatGPT Compromising Enterprise Policies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Corporate data security faces an unprecedented crisis as new research reveals widespread employee misuse of generative AI platforms. A comprehensive study examining enterprise browsing behavior has uncovered alarming patterns of sensitive data exposure across organizations worldwide. The research, based on …

Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have released a full proof-of-concept (PoC) exploit for a high-severity vulnerability in the Linux kernel’s ksmbd module, demonstrating a reliable path to local privilege escalation. The vulnerability, tracked as CVE-2025-37947, is an out-of-bounds write that can be leveraged …

GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could lead to denial-of-service (DoS) attacks and allow unauthorized access. All …

IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond. Initially focused on credential harvesting via …

Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading style sheets (CSS) properties. This attack vector enables threat actors …

Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant Microsoft 365 outage blocked user access to several critical services, including Microsoft Teams, Exchange Online, and the Microsoft 365 admin center. The incident began late on Wednesday, October 8, 2025, leaving organizations worldwide unable to utilize essential communication …

Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular communication platform Discord is facing an extortion attempt following a significant data breach at one of its third-party customer service providers, Zendesk. Threat actors claim to have stolen 1.5 terabytes of sensitive data, including over 2.1 million government-issued …

CrowdStrike Falcon Windows Sensor Vulnerability Enables Code Execution and File Deletion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has disclosed and released patches for two medium-severity vulnerabilities in its Falcon sensor for Windows that could allow an attacker to delete arbitrary files. The security vulnerabilities, designated as CVE-2025-42701 and CVE-2025-42706, require an attacker to have already gained …

FreePBX SQL Injection Vulnerability Exploited to Modify The Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability in FreePBX has emerged as a significant threat to VoIP infrastructure worldwide, enabling attackers to manipulate database contents and achieve arbitrary code execution. FreePBX, a widely deployed PBX system built around the open-source Asterisk VoIP …