OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in OAuth2-Proxy, a widely-used reverse proxy that provides authentication services for Google, Azure, OpenID Connect, and numerous other identity providers.  The vulnerability, designated as CVE-2025-54576, enables attackers to bypass authentication mechanisms by manipulating …

Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Linux variant of Gunra ransomware has emerged, marking a significant escalation in the threat group’s cross-platform capabilities since its initial discovery in April 2025. The ransomware, which drew inspiration from the notorious Conti ransomware techniques, has rapidly …

Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into …

ChatGPT, Gemini, GenAI Tools Vulnerable to Man-in-the-Prompt Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting popular AI tools, including ChatGPT, Google Gemini, and other generative AI platforms, exposes them to a novel attack vector dubbed “Man-in-the-Prompt.”  The research reveals that malicious browser extensions can exploit the Document Object Model (DOM) to …

New JSCEAL Attack Targeting Crypto App Users To Steal Credentials and Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign targeting cryptocurrency application users has emerged, leveraging compiled JavaScript files and Node.js to steal digital wallets and credentials with unprecedented stealth. The campaign, dubbed JSCEAL, represents a significant evolution in cybercriminal tactics, utilizing advanced evasion …

Free Decryptor Released for AI-Assisted FunkSec Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have successfully developed and released a free decryption tool for the FunkSec ransomware, a malicious strain that leveraged artificial intelligence capabilities to enhance its operations. The ransomware campaign, which targeted 113 victims between December 2024 and March 2025, …

CISA and FBI Shared Tactics, Techniques, and Procedures of Scattered Spider Hacker Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released an updated joint cybersecurity advisory detailing the sophisticated tactics employed by the Scattered Spider cybercriminal group, also known as UNC3944, Oktapus, and Storm-0875. This threat …

AI Vibe Coding Platform Hacked – Logic Flaw Exposes Private App Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe authentication bypass vulnerability in Base44, a popular AI-powered vibe coding platform recently acquired by Wix, could have allowed attackers unauthorized access to private enterprise applications and sensitive corporate data. The vulnerability, which was patched within 24 hours of …

Qilin Ransomware Gain Traction Following Legal Assistance Option for Ransomware Affiliates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape witnessed a concerning evolution in June 2025 when the Qilin ransomware gang announced a groundbreaking addition to their criminal enterprise: on-demand legal assistance for their affiliates. This announcement, made on a Russian-speaking darknet forum, represents a sophisticated …

BulletProof Hosting Provider Qwins Ltd Fueling Global Malware Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated bulletproof hosting operation has emerged as a critical enabler of global malware campaigns, with cybersecurity researchers uncovering extensive evidence linking UK-registered company Qwins Ltd to widespread cybercriminal activities. The company, operating under Autonomous System Number (ASN) 213702, has …