Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed four elevation of privilege vulnerabilities in its Windows Defender Firewall service, all rated as “Important” in severity. The security flaws were detailed in Microsoft’s September 9, 2025, security update release. If exploited, these vulnerabilities could allow an …

Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially announced a multi-phase plan to deprecate VBScript in Windows, a move that signals a significant shift for developers, particularly those working with Visual Basic for Applications (VBA). The change, first detailed in May 2024, will gradually phase …

Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has issued a warning regarding highly sophisticated “mercenary spyware” attacks targeting a select group of its users. The company’s threat notification system is designed to alert and support individuals who may have been targeted due to their profession or …

VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has released VirtualBox 7.2.2, a maintenance update for its open-source virtualization platform, focusing on improving stability and addressing a range of bugs. Released on September 10, 2025, this version comes as a follow-up to the major 7.2 release, which …

Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is investigating a significant Exchange Online service disruption that is preventing users in North and South America from accessing their mailboxes. The ongoing incident, tracked under the ID EX1151485 in the admin center, impacts all methods of connecting to …

Microsoft Teams Introduces Automatic Alerts for Malicious Links from Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft will enhance security for its Teams platform by automatically warning users about malicious links in chat messages. The new feature, part of Microsoft Defender for Office 365, is designed to protect users from phishing, spam, and malware attacks by …

Business speed, lasting security: Conversation with Amazon’s Senior Software Development Engineer Naman Jain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

To ensure the security of sensitive internet data, it takes more than encryption; it requires clear principles, careful design, and evidential support. Naman Jain is a Senior Software Development Engineer and a leading practitioner in secure systems for fintech and …

PhishKit Evasion Tactics: What You Need to Pay Attention to Right Now 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyber attackers constantly refine their evasion methods. That’s what makes threats, including phishing, increasingly hard to detect and investigate. Kits like Tycoon 2FA regularly evolve with new tricks added to their arsenal. They slip past defenses and compromise companies, demonstrating …

New VMScape Spectre-BTI Attack Exploits Isolation Gaps in AMD and Intel CPUs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel speculative execution attack named VMSCAPE allows a malicious virtual machine (VM) to breach its security boundaries and steal sensitive data, like cryptographic keys, directly from its host system. The vulnerability, identified as CVE-2025-40300, affects a wide range of …

Threat Actors Leveraging Open-Source AdaptixC2 in Real-World Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In early May 2025, security teams began observing a sudden rise in post-exploitation activity leveraging an open-source command-and-control framework known as AdaptixC2. Originally developed to assist penetration testers, this framework offers a range of capabilities—file system manipulation, process enumeration, and …