Apple CarPlay Exploited To Gain Root Access By Executing Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At the recent DefCon security conference, researchers demonstrated a critical exploit chain that allows attackers to gain root access on vehicle infotainment systems by targeting Apple CarPlay. The multi-stage attack, named “Pwn My Ride,” leverages a series of vulnerabilities in …

New Gentlemen Ransomware Leverages Legitimate Drivers, Group Policies to Infiltrate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security researchers have observed a surge in activity by a previously undocumented ransomware group known as The Gentlemen. This threat actor has rapidly distinguished itself through the deployment of highly specialized tools and meticulous reconnaissance tactics, targeting …

GitLab Patches Multiple Vulnerabilities That Enables Denial Of Service and SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security patches for its Community (CE) and Enterprise (EE) editions, addressing multiple vulnerabilities, including two high-severity flaws that could lead to Server-Side Request Forgery (SSRF) and Denial of Service (DoS) attacks. The company is strongly advising …

Top 10 Best Mobile Application Penetration Testing Companies in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-quality mobile application penetration testing company is essential for businesses that want to safeguard their digital assets and user data. These specialized firms employ ethical hackers who simulate real-world cyberattacks to identify and exploit vulnerabilities within mobile apps. The …

Google Drive Desktop for Windows Vulnerability Grants Full Access to Another User’s Drive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been found in the Google Drive Desktop application for Windows. It allows a logged-in user on a shared machine to access another user’s Drive files completely without needing their credentials. This vulnerability stems from a broken …

Microsoft Warns of Active Directory Domain Services Vulnerability, Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an updated warning for a critical security vulnerability in Active Directory Domain Services, tracked as CVE-2025-21293. This flaw could permit an attacker who has already gained initial access to a system to escalate their privileges, potentially gaining …

Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were disclosed on September 9, 2025, and affect various versions of …

HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns. The bug bounty …

Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophos has resolved an authentication bypass vulnerability in its AP6 Series Wireless Access Points that could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security testing and has released a firmware update to address it. …

Windows BitLocker Vulnerability Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry an “Important” severity rating. Both vulnerabilities could allow an authorized …