WhatsApp Exploit Privately Disclosed To Meta At The Pwn2Own Ireland

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At Pwn2Own Ireland 2025 hacking competition, cybersecurity researchers from Team Z3 have withdrawn their high-stakes demonstration of a potential zero-click remote code execution (RCE) vulnerability in WhatsApp, opting instead for a private coordinated disclosure to Meta. The event, held in …

Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The hacking community celebrated the end of Pwn2Own Ireland 2025. Researchers demonstrated their skills by identifying 73 unique zero-day vulnerabilities across different devices. The event, hosted by the Zero Day Initiative (ZDI), distributed a staggering $1,024,750 in prizes, highlighting the …

New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spearphishing campaign has emerged targeting humanitarian organizations and Ukrainian government agencies, leveraging weaponized PDF attachments and fake Cloudflare verification pages to distribute a dangerous WebSocket-based remote access trojan. The operation, first uncovered in early October 2025, demonstrates a …

Amazon Uncovers Root Cause of Major AWS Outage That Brokes The Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS), the backbone for countless websites and services, faced a severe outage last weekend that disrupted operations for millions. The incident, which unfolded in the early hours of October 20, 2025, exposed vulnerabilities in even the most …

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email phishing attacks have reached a critical inflection point in 2025, as threat actors deploy increasingly sophisticated evasion techniques to circumvent traditional security infrastructure and user defenses. The threat landscape continues to evolve with the revival and refinement of established …

Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing …

Toys “R” Us Canada Confirms Data Breach – Customers Personal Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Toys “R” Us Canada has alerted customers to a significant data breach that potentially exposed their personal information, marking another blow to consumer trust in retail data security. In emails dispatched to affected individuals this morning, the popular toy retailer …

New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent of detected cases. In a notable shift from traditional deployment …

HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version 1.2.50.9581 of the agent, pushed silently to HP’s Next Gen AI systems like the EliteBook …

Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations’ critical code repositories and sensitive data. This emerging threat exploits misconfigured storage access controls to establish persistence and …