Apache Jena Vulnerability Leads to Arbitrary File Access or Manipulation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache Jena has disclosed two significant security vulnerabilities affecting versions through 5.4.0, prompting an immediate upgrade recommendation to version 5.5.0.  Both CVE-2025-49656 and CVE-2025-50151, announced on July 21, 2025, represent important severity flaws that exploit administrative access to compromise server …

UK Confirms Ban of Ransomware Payments to Public and Critical National Infrastructure Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK government has announced comprehensive measures to tackle ransomware attacks, with public sector organizations and critical national infrastructure operators facing an outright ban on paying ransom demands to cyber criminals.  This landmark decision, supported by nearly three-quarters of consultation …

ETQ Reliance RCE Vulnerability Enables Full SYSTEM Access Just by Typing a Single Space

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in ETQ Reliance quality management software allows attackers to gain full administrative access by simply adding a single space character to a login attempt.  The flaw, tracked as CVE-2025-34143, represents one of the most unusual authentication bypass …

New Scanner Released to Detect SharePoint Servers Vulnerable to 0-Day Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source scanning tool has been released to identify SharePoint servers vulnerable to the critical zero-day exploit CVE-2025-53770.  The newly published scanner, available on GitHub, enables organizations to rapidly assess their SharePoint infrastructure for this unauthenticated Remote Code Execution vulnerability …

Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple security vulnerabilities affecting Sophos firewall products, with two enabling pre-authentication remote code execution that could allow attackers to compromise systems without valid credentials.  The vulnerabilities, tracked as CVE-2025-6704, CVE-2025-7624, CVE-2025-7382, CVE-2024-13974, and CVE-2024-13973, impact various configurations of Sophos Firewall …

Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Systems has issued a critical security advisory warning of multiple remote code execution vulnerabilities in its Identity Services Engine (ISE) that are being actively exploited by attackers in the wild. The vulnerabilities, carrying the maximum CVSS severity score of …

UK Sanctions Russian APT 28 Hackers for Attacking Microsoft Cloud Service Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK Government has imposed sanctions on Russian military intelligence units and 18 individuals following the exposure of a sophisticated cyber espionage campaign targeting Microsoft cloud services.  The National Cyber Security Centre (NCSC) revealed that the Russian Advanced Persistent Threat …

New DCHSpy Android Malware Steals WhatsApp Data, Call Logs, Record Audio and Take Photos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of DCHSpy Android surveillanceware, deployed by the Iranian cyber espionage group MuddyWater just one week after escalating tensions in the Israel-Iran conflict.  This malicious tool represents a significant evolution in mobile surveillance capabilities, targeting sensitive communications …

ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in ExpressVPN Windows desktop application that could expose users’ real IP addresses when using Remote Desktop Protocol (RDP) connections.  The flaw, discovered through the company’s bug bounty program, affected specific versions of the Windows client and …

Threat Actors Combine Android Malware With Click Fraud Apps to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of malicious Android Package Kit (APK) files is weaving together two of cybercrime’s most reliable revenue streams—click-fraud advertising and credential theft—into a single, adaptable threat that has begun circulating across Southeast Asia, Latin America, and parts of …