Doctors Imaging Group Suffers Data Breach – 171800+ Users Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Doctors Imaging Group, a healthcare provider based in Florida, has reported a significant data breach that exposed the sensitive personal and medical information of over 171,800 individuals. The incident, classified as a “Hacking/IT Incident,” involved unauthorized access to the organization’s …

Forensic-Timeliner – Windows Forensic Tool for DFIR Investigators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Forensic-Timeliner, a Windows forensic tool for DFIR investigators, has released version 2.2, which offers enhanced automation and improved artifact support for digital forensics and incident response operations. This high-speed processing engine consolidates CSV output from leading triage utilities into a …

NCSC Warns of Oracle E-Business Suite 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NCSC has issued an urgent warning regarding a critical zero-day flaw in Oracle E-Business Suite (EBS) that is currently being exploited in the wild.  Tracked as CVE-2025-61882, the vulnerability resides in the BI Publisher Integration component of Oracle Concurrent Processing …

Zabbix Agent and Agent 2 for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Zabbix Agent and Agent 2 for Windows that allows attackers with local system access to escalate their privileges through DLL injection attacks.  The flaw, tracked as CVE-2025-27237 with a CVSS score of …

Google Chrome RCE Vulnerability Details Released Along with Exploit Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have published the full technical details and exploit code for a critical remote code execution (RCE) vulnerability in Google Chrome’s V8 JavaScript engine.  Tracked internally as a WebAssembly type canonicalization bug, the flaw stems from an improper nullability check …

Microsoft Teams Set to Introduce Highly Anticipated Multitasking Functionality

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is set to roll out a highly anticipated multitasking feature for its Teams platform, which will allow users to open channels in separate windows. This long-awaited update, scheduled for release in November, addresses one of the most common user …

Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the Gemini Command-Line Interface (CLI). This new open-source package integrates Google’s powerful Gemini AI directly into the terminal, offering penetration …

PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A publicly available proof-of-concept (PoC) exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) flaw in the Sudo utility that can grant root access under specific configurations.  Security researcher Rich Mirch is credited with identifying the weakness, while …

Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that utilize the Lua scripting engine, presenting a significant threat to …

Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique uncovered where threat actors abuse Amazon Web Services‘ X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be weaponized for malicious purposes. AWS X-Ray, designed to help developers …