Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The …

HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and access Vault without valid credentials. The vulnerability, tracked as CVE-2025-13357, affects organizations using LDAP authentication with Vault. The security issue …

Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register …

Top 10 Best Exposure Management Tools In 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Exposure Management is a proactive cybersecurity discipline that systematically identifies, assesses, prioritizes, and remediates security vulnerabilities and misconfigurations across an organization’s entire attack surface both internal and external. Unlike traditional, periodic vulnerability scanning, EM leverages continuous monitoring, threat intelligence, and …

ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of ClickFix attacks is abusing highly realistic fake Windows Update screens and PNG image steganography to secretly deploy infostealing malware such as LummaC2 and Rhadamanthys on victim systems. The campaigns rely on tricking users into manually running …

NVIDIA’s Isaac-GROOT Robotics Platform Vulnerability Let Attackers Inject Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has disclosed two critical code injection vulnerabilities affecting its Isaac-GR00T robotics platform. The vulnerabilities, tracked as CVE-2025-33183 and CVE-2025-33184, exist within Python components and could allow authenticated attackers to execute arbitrary code, escalate privileges, and alter system data. The …

Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign targeting Brazilian users has emerged, using WhatsApp as its primary distribution channel to spread banking trojans and harvest sensitive information. This sophisticated attack leverages social engineering by exploiting the trust victims place in their existing contacts, …

Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tel Aviv, Israel, November 24th, 2025, CyberNewsWire Blast is introducing a new operating model for cloud security with a first-of-its-kind Preemptive Cloud Defense Platform, replacing reactive response with continuous prevention. Blast Security, a cybersecurity startup founded by industry veterans from …

PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit has been publicly released for CVE-2025-9501, a critical, unauthenticated command-injection vulnerability affecting W3 Total Cache, one of WordPress’s most widely deployed caching plugins. With over 1 million active installations, the vulnerability poses a significant risk to countless …

Sha1-Hulud Supply Chain Attack: 800+ npm Packages and Thousands of GitHub Repos Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive resurgence of the Sha1-Hulud supply chain malware has struck the open-source ecosystem, compromising over 800 npm packages and tens of thousands of GitHub repositories in a campaign the attackers have dubbed “The Second Coming.” This sophisticated wave targets …