Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PortSwigger has enhanced Burp Suite’s scanning arsenal with the latest update to its ActiveScan++ extension, introducing detection for the critical React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478). This server-side request forgery (SSRF) flaw in React applications allows attackers to execute arbitrary shell …

Apple, Google and Samsung May Enable Always-On GPS in India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Indian government is currently evaluating a controversial proposal from the telecom industry that would mandate smartphone manufacturers to enable “always-on” satellite location tracking. This move has sparked significant opposition from major technology companies, including Apple, Google, and Samsung, who …

Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A deceptive Android application lurking in the Google Play Store, disguised as a document reader and file manager, but delivering the Anatsa banking trojan to users. Cybersecurity firm Zscaler ThreatLabz found an app named “Document Reader – File Manager” by …

Hackers Exploit AWS IAM Eventual Consistency for Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical persistence technique in AWS Identity and Access Management (IAM) stemming from its eventual consistency model, allowing attackers to retain access even after defenders delete compromised access keys. AWS IAM, like many distributed systems, employs eventual consistency to scale …

New GhostFrame Super Stealthy Phishing Kit Attacks Millions of Users Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing kit called GhostFrame has already been used to launch over 1 million attacks. First discovered in September 2025 by Security researchers at Barracuda, this stealthy tool represents a dangerous evolution in phishing-as-a-service technology. What makes GhostFrame …

INE Earns G2 Winter 2026 Badges Across Global Markets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cary, North Carolina, USA, December 4th, 2025, CyberNewsWire Cybersecurity and IT training platform maintains Leader and Momentum Leader positions while expanding regional excellence INE has been recognized with seven G2 Winter 2026 badges, underscoring its continued leadership in online course …

FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new alert warns people about a growing scam that uses altered photos to trick families into paying fake ransom demands. In a notice titled Alert Number: I-120525-PSA, dated December 5, 2025. The FBI explains that criminals are taking photos …

QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QuasarRAT, initially surfacing in 2014 under the alias xRAT, began its lifecycle as a legitimate remote administration tool for Windows environments. Over the last decade, however, its open-source nature and accessibility have facilitated its transformation into a potent instrument for …

NVIDIA and Lakera AI Propose Unified Framework for Agentic System Safety

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As artificial intelligence systems become more autonomous, their ability to interact with digital tools and data introduces complex new risks. Recognizing this challenge, researchers from NVIDIA and Lakera AI have collaborated on a new paper proposing a unified framework for …

Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have exposed a critical privacy flaw dubbed “Careless Whisper” that lets attackers monitor user activity on WhatsApp and Signal through silent delivery receipts, without alerting victims or needing prior contact. By crafting stealthy messages like reactions to nonexistent …