CISA Warns of Gladinet CentreStack and Triofox Files Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms. The flaw, tracked as CVE-2025-11371, exposes sensitive system files and directories to unauthorized external access, potentially compromising organizations …

Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has rolled out an urgent security patch for its Chrome browser, addressing five vulnerabilities that could enable attackers to execute malicious code remotely. The update, version 142.0.7444.134/.135 for Windows, 142.0.7444.135 for macOS, and 142.0.7444.134 for Linux, targets critical flaws …

Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

European organizations are facing an unprecedented wave of ransomware attacks as cybercriminals increasingly integrate artificial intelligence tools into their operations. Since January 2024, big game hunting threat actors have named approximately 2,100 Europe-based victims on more than 100 dedicated leak …

Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A privilege escalation flaw in Windows Cloud Files Mini Filter Driver has been discovered, allowing local attackers to bypass file write protections and inject malicious code into system processes. Security researchers have uncovered CVE-2025-55680, a high-severity privilege-escalation vulnerability in the …

October Sees Rise in Phishing and Ransomware Attacks, Including TyKit and Google Careers Scams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

October 2025 marked a notable escalation in cyber threats, with phishing campaigns and ransomware variants exploiting trusted cloud services to target corporate credentials and critical infrastructure. Attackers increasingly abused platforms like Google, Figma, and ClickUp for credential theft, while LockBit’s …

AI Engine WordPress Plugin Exposes 100,000 WordPress Sites to Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in the AI Engine WordPress plugin has put more than 100,000 active installations at risk of privilege escalation attacks. The flaw, tracked as CVE-2025-11749 with a CVSS score of 9.8, allows unauthenticated attackers to extract bearer …

HackedGPT – 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Seven critical vulnerabilities in OpenAI’s ChatGPT, affecting both GPT-4o and the newly released GPT-5 models, that could allow attackers to steal private user data through stealthy, zero-click exploits. These flaws exploit indirect prompt injections, enabling hackers to manipulate the AI …

Curly COMrades Hacker Group Using New Tools to Create Hidden Remote Access on Compromised Windows 10

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated threat actor known as Curly COMrades has deployed an innovative attack methodology that leverages legitimate Windows virtualization features to establish covert, long-term access to victim networks. The campaign, which began in early July 2025, represents a significant evolution …

Guide to Choosing the Best Free Backup Software for Secure, Reliable Cloud Backup

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Any individual heavily depends on data as their most critical asset: from memorable photos to important work documents, everything must be safeguarded properly. Why? Simply because you can never predict what might happen to your data: you could lose your …

FIN7 Hackers Using Windows SSH Backdoor to Establish Stealthy Remote Access and Persistence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious FIN7 threat group, also known by the nickname Savage Ladybug, continues to pose a significant risk to enterprise environments through an increasingly refined Windows SSH backdoor campaign. The group has been actively deploying this sophisticated backdoor mechanism to …