Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code and bypass essential security features. Adobe issued security bulletin APSB25-119 on December 9, 2025, with a priority rating of 3, affecting both …

Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an urgent security update for the Chrome browser to address a high-severity zero-day vulnerability that is currently being exploited in the wild. This emergency patch is part of the latest Stable channel update, bringing the version to …

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers to hijack administrator sessions without authentication. The vulnerability, identified as CVE-2025-10573, has been assigned a CVSS score of 9.6 and …

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to their scanning methodologies, researchers have identified a massive attack surface comprising over 165,000 …

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for financial fraud. This toolkit, observed by Varonis, allows threat actors, even those with minimal technical skill, to spin up pixel-perfect …

What’s Next for SOC in 2026: Get the Early-Adopter Advantage 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity is about to hit a turning point in 2026. Attackers aren’t only testing AI but also building campaigns around it. Their tooling is getting faster, more adaptive, and far better at mimicking user behavior, from reconnaissance to phishing to initial access.  The Shift is Already …

Threat Actors Weaponize ChatGPT and Grok Conversations to Deploy AMOS Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are now leveraging the trust users place in AI platforms like ChatGPT and Grok to distribute the Atomic macOS Stealer (AMOS). A new campaign discovered by Huntress on December 5, 2025, reveals that attackers have moved beyond mimicking …

Microsoft Outlook Vulnerability Let Attackers Execute Malicious Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical remote code execution (RCE)vulnerability in Outlook that could allow attackers to execute malicious code on vulnerable systems. The flaw, tracked as CVE-2025-62562, was released on December 9, 2025, and requires immediate attention from IT administrators …

North Korean Hackers Exploit React2Shell Vulnerability in the Wild to Deploy EtherRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier. On December 5, 2025, just two days after the disclosure …

FortiSandbox OS command injection Vulnerability Let Attackers execute Malicious code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has released a critical security update for its FortiSandbox analysis appliances to fix a dangerous vulnerability. If left unpatched, this flaw could allow attackers to take control of the underlying system. The vulnerability, tracked as CVE-2025-53949, was officially published on …