PoC exploit Released for VMware Workstation guest-to-host escape Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical vulnerability chain in VMware Workstation that allows an attacker to escape from a guest virtual machine and execute arbitrary code on the host operating system. The exploit successfully chains together …

Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An extortion group known as the Crimson Collective claims to have breached Red Hat’s private GitHub repositories, making off with nearly 570GB of compressed data from 28,000 internal repositories. This data theft is being regarded as one of the most …

Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code. The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that …

Microsoft Outlook for Windows Bug Leads to Crash While Opening Email

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed it is investigating a significant bug in the classic Outlook for Windows desktop client that causes the application to fail upon launch. The issue, which appears to be linked to Microsoft Exchange logon attempts, prevents users from …

Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has released patches for multiple vulnerabilities in its Enterprise and Cloud Platform products, some of which could allow attackers to execute unauthorized JavaScript code, access sensitive information, or cause a denial-of-service (DoS) condition. The advisories, published on October 1, …

Ukraine Warns of Weaponized XLL Files Delivers CABINETRAT Malware Via Zip Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian security agencies have issued an urgent warning regarding a sophisticated malware campaign targeting government and critical infrastructure sectors through weaponized XLL files distributed via compressed archives. The malicious campaign leverages Microsoft Excel add-in files containing the CABINETRAT backdoor, representing …

Threat Actors Leveraging Senior Travel Scams to Deliver Datzbro Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated Android malware campaign targeting seniors through fraudulent travel and social activity promotions on Facebook. The newly identified Datzbro malware represents a dangerous evolution in mobile threats, combining advanced spyware capabilities with remote access tools …

Malicious PyPI Package Mimics as SOCKS5 Proxy Tool Attacking Windows Platforms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malicious package has infiltrated the Python Package Index (PyPI), masquerading as a legitimate SOCKS5 proxy tool while harboring backdoor capabilities that target Windows systems. The SoopSocks package, tracked as XRAY-725599, presents itself as a benign networking utility that …

New Google Drive Desktop Feature adds AI-powered Ransomware Detection to Prevent Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has introduced a new AI-powered ransomware detection feature for Google Drive for desktop, designed to block cyberattacks and protect user files automatically. This enhancement adds a significant layer of security for users of Windows and macOS, addressing the persistent …

New FlipSwitch Hooking Technique Bypasses Linux Kernel Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape witnessed the emergence of a sophisticated rootkit variation, FlipSwitch, targeting modern Linux kernels. First surfacing in late September 2025, FlipSwitch exploits recent changes in syscall dispatching to implant stealthy hooks directly into kernel code. Early indicators suggest …