Critical WatchGuard Vulnerability Allows Unauthenticated Attacker to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in WatchGuard’s Firebox firewalls, which could allow a remote, unauthenticated attacker to execute arbitrary code on affected devices. The flaw, tracked as CVE-2025-9242, has been assigned a critical severity rating with a CVSS score …

Python Based XillenStealer Attacking Windows Users to Steal Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity researchers have observed the emergence of XillenStealer, a Python-based information stealer publicly hosted on GitHub and rapidly adopted by threat actors. First reported in mid-September 2025, the stealer leverages a user-friendly builder GUI to lower the …

Microsoft Introduces Network Strength Indicator With Teams to Clarify Disruptions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is set to roll out a new feature for its Teams platform called the Network Strength Indicator, designed to provide users with greater clarity on call quality and disruptions during meetings. The update seeks to clarify technical issues by …

New Innovative FileFix Attack in The Wild Leverages Steganography to Deliver StealC Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberthreat campaign has emerged that represents a significant evolution in social engineering attacks, introducing the first real-world implementation of FileFix attack methodology beyond proof-of-concept demonstrations. This advanced threat leverages steganography techniques to conceal malicious payloads within seemingly innocent …

Apple Fixes 0-Day Vulnerabilities in Older version of iPhones and iPad

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released iOS 16.7.12 and iPadOS 16.7.12 on September 15, 2025, delivering critical security updates to older-generation devices.  The patches address a zero-day flaw in the ImageIO framework that could allow an attacker to execute arbitrary code by enticing …

40,000+ Cyberattacks Targeting API Environments To Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed an unprecedented surge in API-focused attacks during the first half of 2025, with threat actors launching over 40,000 documented incidents against application programming interfaces across 4,000 monitored environments. This alarming escalation represents a fundamental shift …

Microsoft OneDrive Auto-Sync Exposes Enterprise Secrets in SharePoint Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A default auto-sync feature in Microsoft OneDrive automatically moves local files to SharePoint, creating a significant security risk by exposing sensitive data and secrets on a large scale. Research from Entro Security highlights the severity of the issue, revealing that …

Google Announces Full Availability of Client-Side Encryption for Google Sheets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the full general availability of client-side encryption (CSE) for Google Sheets. This significant upgrade gives organizations direct control over encryption keys and enhances data confidentiality within Google Workspace. This move extends robust security features to spreadsheets, ensuring …

Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities were identified in Chaos Mesh, a popular Cloud Native Computing Foundation chaos engineering platform used for fault injection testing in Kubernetes environments.  The security flaws, collectively dubbed “Chaotic Deputy,” comprise four CVEs that enable complete cluster compromise through …

Kubernetes C# Client Vulnerability Exposes API Server Communication To MiTM Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A medium-severity vulnerability has been discovered in the official Kubernetes C# client, which could allow an attacker to intercept and manipulate sensitive communications. The flaw, rated 6.8 on the CVSS scale, stems from improper certificate validation logic. This weakness exposes …