Critical SonicWall SSL VPN Vulnerability Let Attackers Trigger DoS Attack on Firewalls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in SonicWall Gen7 firewall products could allow remote unauthenticated attackers to cause service disruptions through denial-of-service (DoS) attacks.  The format string vulnerability tracked as CVE-2025-40600 affects the SSL VPN interface of multiple SonicWall firewall models and has …

WordPress Theme RCE Vulnerability Actively Exploited to Take Full Site Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability in the popular “Alone” WordPress theme is being actively exploited by attackers to gain complete control of vulnerable websites.  The vulnerability, assigned CVE-2025-5394 with a maximum CVSS score of 9.8, affects over 9,000 …

Lumma Password Stealer Attack Infection Chain and Its Escalation Tactics Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has witnessed a significant surge in information-stealing malware, with Lumma emerging as one of the most prevalent and sophisticated threats targeting Windows systems globally. This C++-based information stealer has rapidly gained traction in underground markets, establishing itself …

BeyondTrust Privilege Management for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in BeyondTrust’s Privilege Management for Windows solution, allowing local authenticated attackers to escalate their privileges to the administrator level.  The flaw, designated as CVE-2025-2297 with a CVSSv4 score of 7.2, affects all versions …

Global Authorities Shared IoCs and TTPs of Scattered Spider Behind Major ESXi Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Joint international advisory warns of evolving social engineering tactics and new DragonForce ransomware deployment targeting commercial facilities A collaboration of international cybersecurity agencies issued an urgent updated advisory on July 29, 2025, highlighting the escalating threat posed by the Scattered …

10 Best Dark Web Monitoring Tools in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Monitoring and tracking actions on the dark web, a section of the internet that is hidden and requires particular software and configurations to access, is called monitoring. The selling of stolen data, illegal drugs, illegal weapons, hacking services, and other …

ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ChatGPT agents demonstrate the ability to autonomously bypass Cloudflare’s CAPTCHA verification systems, specifically the ubiquitous “I am not a robot” checkbox.  This development, first documented in a viral Reddit post on the r/OpenAI community, showcases the evolving sophistication of AI …

Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.  In April 2025, …

Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Enterprise applications integrating Large Language Models (LLMs) face unprecedented security vulnerabilities that can be exploited through deceptively simple prompt injection attacks.  Recent security assessments reveal that attackers can bypass authentication systems, extract sensitive data, and execute unauthorized commands using nothing …

Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a comprehensive defense-in-depth strategy to combat indirect prompt injection attacks, one of the most significant security threats facing large language model (LLM) implementations in enterprise environments.  The company’s multi-layered approach combines preventative techniques, detection tools, and impact …