CISA Warns of Apple WebKit Vulnerability 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning regarding a critical zero-day vulnerability in Apple WebKit that is currently being actively exploited in attacks. CISA has added CVE-2025-43529 to its catalog of vulnerabilities requiring immediate attention, setting a strict deadline for organizations to implement …

Fortinet FortiWeb Vulnerability (CVE-2025-64446) Exploited in the Wild for Full Admin Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have been actively exploiting a critical path-traversal vulnerability in Fortinet’s FortiWeb web application firewall since early October 2025, allowing unauthenticated attackers to create rogue administrator accounts and gain full control of exposed devices. Researchers at watchTowr Labs first detailed the …

Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new local privilege escalation vulnerability in Microsoft’s Windows Admin Center (WAC), affecting versions up to 2.4.2.1 and environments running WAC 2411 and earlier. Tracked as CVE-2025-64669, the flaw stems from insecure directory permissions on the folder C:ProgramDataWindowsAdminCenter, which is …

NoName057(16) Hackers Using DDoSia DDoS Tool to Attack Organizations in NATO

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NoName057(16), also known as 05716nnm or NoName05716, has emerged as a significant threat targeting NATO member states and European organizations. The group, which originated as a covert project within Russia’s Centre for the Study and Network Monitoring of the Youth …

Dark Web Omertà Market Shut Downed Following the Leak of Real Server IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The dark web landscape constantly shifts between emerging platforms and sudden closures, often driven by the very anonymity they promise. On November 21, 2025, a new contender named Omertà Market emerged, positioning itself as a bastion of stability and security. …

FreePBX Vulnerabilities Enables Authentication Bypass that Leads Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FreePBX has addressed critical vulnerabilities enabling authentication bypass and remote code execution in its Endpoint Manager module. Discovered by Horizon3.ai researchers, these flaws affect telephony endpoint configurations in the open-source IP PBX system. Researchers identified three high-severity issues distinct from …

Malicious NuGet Package Uses .NET Logging Tool to Steal Cryptocurrency Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape has once again been rattled by a subtle yet dangerous supply chain attack. A malicious NuGet package named Tracer.Fody.NLog was discovered masquerading as a legitimate .NET tracing library. Published in 2020, this package successfully deceived developers for …

Popular Chrome Extension with Over 6 Million Installs Captures User Inputs to AI Chatbots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widely trusted Chrome extension with more than 6 million users has been discovered secretly collecting and selling conversations from major AI platforms. Urban VPN Proxy, which carries Google’s “Featured” badge indicating it passed manual review for quality standards, contains …

SoundCloud Confirms Data Breach – Hackers Exfiltrated User Account Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SoundCloud has confirmed a security incident involving unauthorized access to user data, revealing that hackers exfiltrated email addresses and public profile information from approximately 20% of its user base. The company disclosed the breach in a transparency blog post on …

New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered account takeover campaign targeting WhatsApp users demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities. The threat, identified as the GhostPairing Attack, uses social engineering and WhatsApp’s legitimate device linking feature to …