Cisco ASA/FTD 0-Day Vulnerability Exploited for Authentication Bypass – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has released advisories for a zero-day exploit chain affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, which is reportedly being used in highly targeted attacks by an unknown threat actor. According to …

Red Hat Breach Exposes 5000+ High Profile Enterprise Customers at Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack has compromised Red Hat Consulting’s infrastructure, potentially exposing sensitive data from over 5,000 enterprise customers worldwide. The breach, executed by the extortion group Crimson Collective, has raised serious concerns about the security of critical business documentation and …

GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical deserialization flaw in GoAnywhere MFT’s License Servlet, tracked as CVE-2025-10035, has already been weaponized by the Storm-1175 group to execute the Medusa ransomware. The vulnerability affects GoAnywhere MFT versions up to 7.8.3. It resides in the License Servlet …

Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has released a security advisory detailing a medium-severity vulnerability in the Kibana CrowdStrike Connector that could allow for the exposure of sensitive credentials. The flaw, tracked as CVE-2025-37728, affects multiple versions of Kibana and could allow a malicious user …

CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent security advisory, adding Microsoft Windows privilege escalation vulnerability CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025.  The vulnerability affects the Microsoft Windows Common Log File System (CLFS) Driver and poses significant …

OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim’s machine. The vulnerability is a bypass of a previous fix for a similar issue …

Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch their systems.  The vulnerability, carrying a maximum CVSS score of …

13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 13-year-old critical remote code execution (RCE) vulnerability in Redis, dubbed RediShell, allows attackers to gain full access to the underlying host system. The flaw, tracked as CVE-2025-49844, was discovered by Wiz Research and has been assigned the highest possible …

Reemo Unveils Bastion+: A Scalable Solution for Global Privileged Access Management

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paris, France, October 6th, 2025, CyberNewsWire Reemo continues its mission to secure enterprise remote access and becomes the first French cybersecurity provider to protect all remote access within a single platform. Reemo announces Bastion+, a next-generation bastion solution deployable without …

Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed responsibility for a significant data breach at Huawei Technologies, a multinational technology corporation based in China. The actor is reportedly attempting to sell what they allege is the company’s internal source code and development tools …