Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input.​ The security flaw resides in the TGZfname() function of …

New Research Uncovers 28 Unique IP Addresses and 85 Domains Hosting Carding Markets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent investigation has exposed the technical foundation of underground carding operations, revealing 28 unique IP addresses and 85 domains actively hosting illegal marketplaces where stolen credit card data is bought and sold. These platforms operate as sophisticated e-commerce sites …

New ‘Penguin’ Pig Butchering as a Service Selling PII, Stolen Accounts and Fraud Kits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The world of cybercrime has taken a dangerous turn as pig butchering scams now operate as turnkey services, lowering entry barriers for bad actors worldwide. The “Penguin” operation represents a growing marketplace that provides everything scammers need to launch large-scale …

New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher TwoSevenOneT, known for EDR evasion tools like EDR-Freeze and EDR-Redir, unveiled EDRStartupHinder this week. The tool blocks antivirus and EDR services at startup by redirecting critical System32 DLLs via Windows Bindlink, demonstrated on Windows Defender in Windows 11 …

Instagram Confirms no System Breach and Fixed External Party Password Reset Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Instagram has stated that its systems were not breached and that recent password reset emails some users received were triggered by an external party abusing a now-fixed issue. The company says user accounts remain secure and that the unexpected reset …

Network Security Checklist – Complete Guide To Protect Enterprise Networks (2026)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Network security is paramount in today’s digital landscape, where organizations face increasingly sophisticated threats. This guide presents a detailed Network Security checklist with examples to help you establish robust protection and minimize vulnerabilities. Network Security Musts: The 7-Point Checklist – …

Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Open Source Intelligence (OSINT) has become a cornerstone of cybersecurity threat intelligence. In today’s digital landscape, organizations face a constant barrage of cyber threats, ranging from data breaches and phishing attacks to sophisticated nation-state operations. To stay ahead of these …

Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cybersecurity incident at Gulshan Management Services, Inc., a gas station operator based in Sugar Land, Texas, has compromised the personal information of over 377,000 customers. The breach, discovered on September 27, 2025, exposed sensitive data over 10 days from …

New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a new variant of the MacSync malware targeting macOS users. Unlike previous versions that relied on complex ClickFix techniques, this iteration masquerades as a legitimately signed, notarised Apple application, thereby bypassing macOS Gatekeeper security and stealing …

Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security breach has compromised approximately 17.5 million Instagram user accounts, exposing sensitive personal information that is now circulating on the dark web. The incident was discovered and reported by cybersecurity firm Malwarebytes earlier this week, raising urgent concerns …