CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177).  This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor to manipulate linked device synchronization messages and force a target …

PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities.  The flaw resides in the unsafe deserialization of HTTP header contents in …

New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide. First detected in late August 2025, TinyLoader installs multiple secondary payloads—most notably RedLine Stealer and DCRat—transforming …

Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes.  Originally marketed as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed …

AI-Powered Cybersecurity Tools Can Be Turned Against Themselves Through Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered cybersecurity tools can be turned against themselves through prompt injection attacks, allowing adversaries to hijack automated agents and gain unauthorized system access. Security researchers Víctor Mayoral-Vilches & Per Mannermaa Rynning, revealed how modern AI-driven penetration testing frameworks become vulnerable …

Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company’s Salesforce instance. The breach was part of a wider supply chain attack that exploited a vulnerability in the Salesloft Drift chatbot …

ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability discovered in ESPHome’s web server component has exposed thousands of smart home devices to unauthorized access, effectively nullifying basic authentication protections on ESP-IDF platform implementations. The flaw, designated CVE-2025-57808 with a CVSS score of 8.1, affects …

Google Confirms That Claims of Major Gmail Security Warning are False

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially debunked widespread reports claiming the company issued a major security warning to Gmail users, clarifying that such claims are entirely false. The technology giant addressed the misinformation directly on September 1, 2025, emphasizing that no broad security …

New Phishing Attack Via OneDrive Attacking C-level Employees for Corporate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spear-phishing campaign has emerged targeting senior executives and C-suite personnel across multiple industries, leveraging Microsoft OneDrive as the primary attack vector. The campaign utilizes carefully crafted emails masquerading as internal HR communications about salary amendments to trick high-profile …

New Report on Commercial Spyware Vendors Detailing Their Targets and Infection Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Commercial surveillance vendors have evolved from niche technology suppliers into a sophisticated multi-billion-dollar ecosystem that poses unprecedented threats to journalists, activists, and civil society members worldwide. A comprehensive new report by Sekoia.io’s Threat Detection & Research team reveals how these …