BIND 9 Vulnerability Allow Attackers to Crash Server by Sending Malicious Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been disclosed in BIND 9, the widely used DNS server software responsible for domain name resolution across millions of internet services. The vulnerability, tracked as CVE-2025-13878, enables remote attackers to crash DNS servers by sending specially …

New Multi-Stage Windows Malware Disables Microsoft Defender Before Dropping Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a sophisticated multi-stage malware campaign targeting Windows systems through social engineering and weaponized cloud services. The attack employs business-themed documents as deceptive entry points, luring users into extracting compressed archives containing malicious shortcuts that execute PowerShell …

Critical Vulnerability in Binary-Parser Library for Node.js Allows Malicious Code injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical code-injection vulnerability has been identified in the Node.js binary-parser library, affecting all versions before 2.3.0. The flaw allows attackers to execute arbitrary JavaScript code if untrusted input is used to construct parser definitions, potentially compromising application integrity and …

New AI-Android Malware that Auto Clicks Ads from the Infected Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous Android malware campaign has emerged, targeting users through mobile games and pirated streaming app modifications. The threat, known as Android.Phantom, employs machine learning technology to perform automated ad-click fraud on infected smartphones. Over 155,000 downloads of compromised games …

New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the …

Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability, CVE-2026-20045, actively exploited in the wild. Affecting key Unified Communications products, this flaw allows unauthenticated attackers to run arbitrary commands on the underlying OS, potentially gaining root access. The …

Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting full administrative access to internet-exposed devices. Multiple users have reported …

Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, a kernel driver from Adlice Software’s RogueKiller antivirus, and use …

New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has entered a dangerous new chapter with the discovery of VoidLink, the first documented advanced malware framework built almost entirely by artificial intelligence. Unlike earlier attempts where inexperienced hackers used AI to create basic malicious tools, VoidLink …

Microsoft Investigating Issue Impacting Exchange Online, Teams, and M365 Suite

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed it is actively investigating a new service incident affecting multiple core services within the Microsoft 365 ecosystem. The company acknowledged the disruption on Wednesday evening, following reports of connectivity issues and service degradation for users relying on …