Wireshark 4.6.2 Released With Fix for Vulnerabilities, and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark 4.6.2, the latest version of the leading open-source network protocol analyzer, addresses critical crash vulnerabilities and plugin compatibility issues. This maintenance release prioritizes stability for users in troubleshooting and security analysis.​ Developers patched two denial-of-service vulnerabilities identified in recent …

New ARTEMIS AI Agent Outperformed 9 out of 10 Human Penetration Testers in Detecting Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Stanford University, Carnegie Mellon University, and Gray Swan AI have unveiled ARTEMIS, a sophisticated AI agent framework that demonstrates remarkable competitive capabilities against seasoned cybersecurity professionals. In the first-ever comprehensive comparison of AI agents against human experts in …

New Android Malware Mimic as mParivahan and e-Challan Attacking Android Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android malware campaign named NexusRoute is actively targeting Indian citizens by impersonating government services. The operation uses fake versions of the official mParivahan and e-Challan applications to harvest login credentials and financial information from unsuspecting users. This coordinated …

New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel social engineering campaign, dubbed ClickFix, has been identified, which cleverly employs an old Windows command-line tool, finger.exe, to install malware on victims’ systems. This attack begins with a deceptive CAPTCHA verification page, tricking users into running a script …

Shannon – AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shannon is a fully autonomous AI pentesting tool for web applications that identifies attack vectors via code analysis and validates them with live browser exploits. Unlike traditional static analysis tools that merely flag potential issues, Shannon operates as a fully …

Storm-0249 Abusing EDR Process Via Sideloading to Hide Malicious Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Storm-0249, once known primarily as a mass phishing group, has undergone a significant transformation into a sophisticated initial access broker specializing in precision attacks. This evolution marks a critical shift in threat tactics, moving away from noisy phishing campaigns toward …

Microsoft December 2025 Security Updates Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s December 2025 security updates have unleashed an unexpected headache for enterprise admins relying on Message Queuing (MSMQ). Installed via KB5071546 on December 9, the patch targeting OS Build 19045.6691 alters MSMQ’s security model, leading to widespread failures in queue …

New Gentlemen Ransomware Breaching Corporate Networks to Exfiltrate and Encrypt Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Gentlemen ransomware, first identified in August 2025, has rapidly evolved into a significant threat targeting corporate networks globally. Operating on a double extortion model, this group exfiltrates sensitive data before encrypting it, ensuring they can leverage stolen information even if …

Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security issue involving the Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with System privileges. While investigating CVE-2025-59230, the vulnerability that Microsoft addressed in the October 2025 security updates. 0patch security analysts discovered …

CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Sierra Wireless routers has been added to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes after evidence emerged that the flaw is being actively exploited in the wild. Posing significant risks to organizations that still …