Angular Platform Vulnerability Allows Malicious Code Execution Via Weaponized SVG Animation Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical Stored XSS vulnerability in Angular’s template compiler (CVE-2025-66412) allows attackers to execute arbitrary code by weaponizing SVG animation attributes. Bypassing Angular’s built-in security sanitization mechanisms and affecting applications using versions below 19.2.17, 20.3.15, or 21.0.2. The Angular template …

CISA Warns of Iskra iHUB Vulnerability Allowing Remote Device Reconfiguration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical warning regarding a severe authentication vulnerability affecting Iskra’s iHUB and iHUB Lite intelligent metering gateways used in energy infrastructure worldwide. The flaw, tracked as CVE-2025-13510, carries a CVSS v4 severity score of 9.3, indicating an exploit that requires …

Threat Actors Allegedly Promoting Fully Undetectable K.G.B RAT on Hacker Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A concerning development has emerged within the cybercriminal ecosystem as threat actors continue distributing K.G.B RAT, a remote access trojan bundled with advanced detection evasion capabilities. According to recent reports, this tool combination surfaced on underground forums and has caught …

BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced …

Threat Actors Leveraging Matanbuchus Malicious Downloader to Ransomware and Establish Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Matanbuchus represents a significant threat in the cybercriminal landscape as a dangerous malware downloader written in C++. Since 2020, this tool has been sold as Malware-as-a-Service, allowing threat actors to rent access and deploy it against targeted organizations. In July …

Let’s Encrypt to Reduce Certificate Validity from 90 Days to 45 Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt has officially announced plans to reduce the maximum validity period of its SSL/TLS certificates from 90 days to 45 days. The transition, which will be completed by 2028, aligns with broader industry shifts mandated by the CA/Browser Forum …

Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The development team has officially released essential security updates to address two significant vulnerabilities found in the popular web framework. These issues range from high to moderate severity. They could allow attackers to compromise database integrity or crash servers through …

Chrome 143 Released With Fix for 13 Vulnerabilities that Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary …

ChatGPT Down – Users Report Outage Worldwide, Conversations Disappeared for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Millions of users worldwide faced a significant disruption to their workflows early Wednesday morning as ChatGPT suffered a major service outage. The incident, which began shortly before 6:30 AM, rendered the popular AI chatbot inaccessible for many and caused alarming …

Hackers can Hijack Your Dash Cams in Seconds and Weaponize it for Future Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dashcams have become essential devices for drivers worldwide, serving as reliable witnesses in case of accidents or roadside disputes. However, a team of Singaporean cybersecurity researchers has uncovered a disturbing reality: these seemingly harmless devices can be hijacked within seconds …