Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has rolled out security updates for its Endpoint Manager product, addressing three high-severity vulnerabilities that could let authenticated local attackers write arbitrary files anywhere on the system disk. The flaws, if exploited, pose significant risks to enterprise environments by …

Android Remote Data-Wipe Malware Attacking Users Leveraging Google’s Find Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated remote data-wipe attack targeting Android devices has emerged, exploiting Google’s Find Hub service to execute destructive operations on smartphones and tablets across South Korea. This campaign represents the first documented case where state-sponsored threat actors weaponized a legitimate …

Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Synology has released an urgent security update addressing a critical remote code execution vulnerability in BeeStation OS that allows unauthenticated attackers to execute arbitrary code on affected devices. The vulnerability, tracked as CVE-2025-12686 and identified by ZDI-CAN-28275, carries a critical …

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted, plain-text nature of calendar invitations to deliver credential phishing campaigns, malware payloads, and zero-day exploits. Over …

Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages. The threat landscape shifted on November 5, 2025, when researchers identified nine malicious NuGet packages designed to inject destructive payloads into critical infrastructure environments. Published …

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems. The flaw, tracked as CVE-2025-64740, has been assigned a high severity rating with a CVSS score …

Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentication is completed. The security flaw, tracked as CVE-2025-12485, stems from improper privilege management …

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security investigation reveals that 65% of prominent AI companies have leaked verified secrets on GitHub, exposing API keys, tokens, and sensitive credentials that could compromise their operations and intellectual property. The wiz research, which examined 50 leading AI …

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure default configurations that expose SSH access on port 4118 using hardcoded …

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses in traditional email security defenses by targeting the world’s two largest email ecosystems: Microsoft Outlook and Google Gmail. The Q3 …