Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write operations.  Suraj Malhotra shared a detailed exploitation technique leveraging the Low Fragmentation Heap (LFH) mechanism to achieve code execution on …

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish robust command and control infrastructure. These publicly rentable subdomain services, traditionally designed for legitimate hosting purposes, have become the preferred …

Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered DLL hijacking vulnerability in Notepad++, the popular source code editor, could allow attackers to execute arbitrary code on a victim’s machine. Tracked as CVE-2025-56383, the flaw exists in version 8.8.3 and potentially affects all installed versions of …

DataCenter Fire Takes 600+ South Korean Government Websites Offline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fire caused by a lithium-ion battery explosion at a key government data center in South Korea has knocked more than 600 essential services offline, disrupting daily life across the highly digitized nation. The incident, which began Friday night at …

Cybersecurity Newsletter Weekly – Chrome 0-Day, 22.2 Tbps DDOS Attack, Kali Linux Release, Cisco IOS 0-Day and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity was marked by a relentless pace of critical disclosures and unprecedented attack volumes, underscoring the escalating challenges facing defenders. At the forefront was Google’s emergency patch for yet another actively exploited zero-day vulnerability in its Chrome …

Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Google Project Zero researcher has detailed a novel technique for remotely leaking memory addresses on Apple’s macOS and iOS. This method can bypass a key security feature, Address Space Layout Randomization (ASLR), without relying on traditional memory corruption vulnerabilities …

Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search engine results and abused code-signing certificates to deliver the Oyster backdoor malware. The attack was neutralized by Microsoft Defender’s Attack Surface Reduction (ASR) …

Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has emerged in Apache Airflow 3.0.3, exposing sensitive connection information to users with only read permissions. The vulnerability, tracked as CVE-2025-54831 and classified as “important” severity, fundamentally undermines the platform’s intended security model for handling sensitive …

Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal alliance between malware operators and covert North Korean IT workers has emerged as a significant threat to corporate organizations worldwide. This hybrid operation, known as DeceptiveDevelopment, represents a dangerous convergence of traditional cybercrime and state-sponsored activities, targeting …

New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated botnet operation has emerged, employing a Loader-as-a-Service model to systematically weaponize internet-connected devices across the globe. The campaign exploits SOHO routers, IoT devices, and enterprise applications through command injection vulnerabilities in web interfaces, demonstrating an alarming evolution in …