Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A commercial spyware company called Intellexa has exploited 15 zero-day vulnerabilities since 2021 to target iOS and Android users worldwide. The company, known for developing the Predator spyware, continues operations despite being sanctioned by the US government. The threats remain …

Critical React2Shell RCE Vulnerability Exploited in the Wild to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability, tracked as CVE-2025-55182 and dubbed “React2Shell,” is now under active exploitation in the wild. GreyNoise researchers have detected opportunistic, largely automated exploitation attempts targeting the unsafe deserialization flaw in the React Server Components Flight …

Malicious Go Packages Mimic as Google’s UUID Library to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a long-running supply chain attack targeting the Go programming community. The Socket Threat Research Team recently identified two malicious packages. github.com/bpoorman/uuid and github.com/bpoorman/uid. That has been silently stealing data from unsuspecting developers for years. The attack relies on …

NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A unified offensive security toolkit, NETREAPER, developed by OFFTRACKMEDIA Studios, consolidates over 70 penetration testing tools into a single, user-friendly command-line interface. This innovation eliminates the chaos of juggling multiple terminals, forgetting syntax, and managing disparate tools. Before NETREAPER, penetration …

Cybersecurity News Weekly Newsletter – 29.7 Tbps DDoS Attack, Chrome 143, React2Shell Vulnerabilities, and Cloudflare Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week’s cybersecurity landscape featured a record-breaking 29.7 Tbps DDoS attack on a financial institution, leveraging IoT botnets and UDP floods that overwhelmed European networks until mitigated via BGP blackholing by Cloudflare and Akamai, highlighting the need for 5G device …

LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LockBit 5.0 key infrastructure exposed, revealing the IP address 205.185.116.233, and the domain karma0.xyz is hosting the ransomware group’s latest leak site. According to researcher Rakesh Krishnan, hosted under AS53667 (PONYNET, operated by FranTech Solutions), a network frequently abused for …

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In an escalating campaign targeting remote access infrastructure, threat actors have initiated active exploitation attempts against Palo Alto Networks’ GlobalProtect VPN portals. GrayNoise tracking activity report scans and exploitation efforts originating from more than 7,000 unique IP addresses worldwide, raising …

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new Android banking malware named FvncBot was first observed on November 25, 2025. This malicious tool is designed to steal sensitive financial information by logging keystrokes, recording screens, and injecting fake login pages into banking apps. The malware initially spreads …

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows attackers to inject malicious prompts via untrusted user inputs like issue titles or pull request bodies, tricking AI models into …

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web services at risk. On December 3, React disclosed CVE-2025-55182, a critical flaw in React Server Components with a CVSS score …