New AI-Powered Wi-Fi Biometrics WhoFi Tracks Humans Behind Walls with 95.5% Accuracy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhoFi surfaced last on the public repository ArXiv, stunning security teams with a proof-of-concept that turns ordinary 2.4 GHz routers into covert biometric scanners. Unlike camera-based systems, this neural pipeline fingerprints the unique way a body distorts Wi-Fi channel state …

Metasploit Module Released For Actively Exploited SharePoint 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have developed a new Metasploit exploit module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server that are being actively exploited in the wild.  The module, designated as pull request #20409 in the Metasploit Framework repository, addresses CVE-2025-53770 and CVE-2025-53771, …

Chinese Hackers Attacking Windows Systems in Targeted Campaign to Deploy Ghost RAT and PhantomNet Malwares

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat researchers are warning of twin Chinese-nexus espionage operations—“Operation Chat” and “Operation PhantomPrayers”—that erupted in the weeks preceding the Dalai Lama’s 90th birthday, exploiting heightened traffic to Tibetan-themed websites to seed Windows hosts with sophisticated backdoors. By compromising a legitimate …

GitLab Security Update – Patch for Multiple Vulnerabilities in Community and Enterprise Edition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released critical security patches addressing multiple vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with versions 18.2.1, 18.1.3, and 18.0.5 now available for immediate deployment.  The release includes fixes for six distinct security vulnerabilities, including …

SonicWall SMA 100 Vulnerabilities Let Attackers Execute Arbitrary JavaScript Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security vulnerabilities affecting SonicWall SMA 100 series SSL-VPN appliances that could allow remote attackers to execute arbitrary JavaScript code and potentially achieve code execution without authentication.  The vulnerabilities affect SMA 210, 410, and 500v models running firmware version 10.2.1.15-81sv …

Google Launches OSS Rebuild to Strengthen Security of The Open-Source Package Ecosystems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Modern software supply-chains rely on millions of third-party components, making package repositories a lucrative for attackers. Over the past year, a string of high-profile compromises—from the xz-utils backdoor to the solana/webjs typosquatting incident—has shown how stealthy code can poison widely …

AWS Client VPN for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services has disclosed a critical security vulnerability in its Client VPN software for Windows that could allow attackers to escalate privileges and execute malicious code with administrative rights.  The vulnerability, tracked as CVE-2025-8069, affects multiple versions of the …

Stealthy Backdoor in WordPress Plugins Gives Attackers Persistent Access to Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated WordPress malware campaign has been discovered operating through the rarely monitored mu-plugins directory, giving attackers persistent access to compromised websites while evading traditional security measures. The malicious code, identified as wp-index.php, exploits WordPress’s “must-use plugins” functionality to maintain …

New ACRStealer Abuses Google Docs and Steam for C2 Server Via DDR Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the ACRStealer information-stealing malware has emerged, demonstrating advanced evasion techniques and leveraging legitimate platforms for covert command-and-control operations. The malware, which has been actively distributed since early 2024, represents a significant evolution in cybercriminal tactics …

Operation CargoTalon Attacking Russian Aerospace & Defense to Deploy EAGLET Implant

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign dubbed “Operation CargoTalon” has emerged, specifically targeting Russia’s aerospace and defense sectors through carefully crafted spear-phishing attacks. The operation, which surfaced in late June 2025, employs a multi-stage infection chain designed to deploy the EAGLET …