HashiCorp Vault Vulnerability Let Attackers to Crash Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical denial-of-service vulnerability in HashiCorp Vault could allow malicious actors to overwhelm servers with specially crafted JSON payloads, leading to excessive resource consumption and rendering Vault instances unresponsive.  Tracked as CVE-2025-6203 and published on August 28, 2025, the flaw …

MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw in the Mobile Security Framework (MobSF) has been discovered, allowing authenticated attackers to upload and execute malicious files by exploiting improper path validation.  The vulnerability, present in version 4.4.0 and patched in 4.4.1, underscores the importance of …

New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Windows-based keylogger known as TinkyWinkey began surfacing on underground forums in late June 2025, targeting enterprise and individual endpoints with unprecedented stealth. Unlike traditional keylogging tools that rely on simple hooks or user-mode processes, TinkyWinkey leverages dual components—a …

Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code.  These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each carry a CVSS score of 9.8 and exploit buffer-corruption weaknesses …

Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has emerged in Azure Active Directory (Azure AD) configurations that exposes sensitive application credentials, providing attackers with unprecedented access to cloud environments.  This vulnerability centers around the exposure of appsettings.json files containing ClientId and ClientSecret credentials, …

28 Years of Nmap – From Simple Port Scanner to Comprehensive Network Security Suite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nmap has remained at the forefront of network discovery and security assessment for nearly three decades. Originally introduced on September 1, 1997, in Phrack magazine as a modest, 2,000-line Linux-only port scanner, Nmap has since matured into a sprawling toolkit …

Zscaler Confirms Data Breach – Hackers Compromised Salesforce Instance and Stole Customer Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity company Zscaler has confirmed it fell victim to a widespread supply-chain attack that exposed customer contact information through compromised Salesforce credentials linked to marketing platform Salesloft Drift. The breach, disclosed on August 31, 2025, stems from a larger campaign …

The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The recent mass-theft of authentication tokens from Salesloft, whose AI chatbot is used by a broad swath of corporate America to convert customer interaction into Salesforce leads, has left many companies racing to invalidate the stolen credentials before hackers can …

Wireshark 4.4.9 Released With Fix For Critical Bugs and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark team has rolled out version 4.4.9, a maintenance release for the world’s most popular network protocol analyzer. This update focuses on stability and reliability, delivering a series of important bug fixes and enhancing support for several existing protocols. …

Hackers Reportedly Demand Google Fire Two Employees, Threaten Data Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group claiming to be a coalition of hackers has reportedly issued an ultimatum to Google, threatening to release the company’s databases unless two of its employees are terminated. The demand, which appeared in a Telegram post, specifically named Austin …