IBM QRadar SIEM Vulnerability Let Attackers Perform Unauthorized Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical permission misconfiguration in the IBM QRadar Security Information and Event Management (SIEM) platform could allow local privileged users to manipulate configuration files without authorization.  Tracked as CVE-2025-0164, the flaw stems from improper permission assignment and carries a CVSS 3.1 base …

Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Great Firewall of China (GFW) suffered its largest-ever internal data breach. More than 500 GB of sensitive material—including source code, work logs, configuration files, and internal communications—was exfiltrated and published online.  The breach stems from Geedge Networks and the …

DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DarkCloud Stealer has recently emerged as a potent threat targeting financial organizations through convincing phishing campaigns. Adversaries employ weaponized RAR attachments masquerading as legitimate documents to deliver a multi-stage JavaScript-based payload. Upon opening the archive, victims execute a VBE script …

New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emerging in early September 2025, the Yurei ransomware has swiftly drawn attention for its novel combination of Go-based execution and ChaCha20 encryption. First documented on September 5 when a Sri Lankan food manufacturer fell victim, the threat actor behind Yurei …

Top 10 Best Ransomware Protection Solutions in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware continues to be one of the most destructive and pervasive cyber threats facing organizations of all sizes. In 2025, the sophistication of ransomware attacks has reached unprecedented levels, with threat actors employing advanced techniques like double extortion, supply chain …

New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, combines multiple anti-analysis techniques and adversary-in-the-middle (AitM) capabilities to target …

Microsoft Warns Of Windows 11 23H2 Support Ending In 60 Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an official reminder that support for Windows 11 version 23H2 Home and Pro editions is set to expire in approximately 60 days. The end-of-servicing date is scheduled for November 11, 2025, after which these devices will no …

ACR Stealer – Uncovering Attack Chains, Functionalities And IOCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ACR Stealer represents one of the most sophisticated information-stealing malware families actively circulating in 2025, distinguished by its advanced evasion techniques and comprehensive data harvesting capabilities. Originally emerging in March 2024 as a Malware-as-a-Service (MaaS) offering on Russian-speaking cybercrime forums, …

FlowiseAI Password Reset Token Vulnerability Allows Account Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting FlowiseAI’s Flowise platform has been disclosed, revealing a severe authentication bypass flaw that allows attackers to perform complete account takeovers with minimal effort.  The vulnerability tracked as CVE-2025-58434 impacts both cloud deployments at cloud.flowiseai.com and self-hosted …

Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities have been discovered in the Linux Common Unix Printing System (CUPS), exposing millions of systems to remote denial-of-service attacks and authentication bypass exploits.  The vulnerabilities, tracked as CVE-2025-58364 and CVE-2025-58060, affect the core printing infrastructure used across …