Chrome Security Update Patches Critical Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has issued an urgent security update for the Chrome browser on Windows, Mac, and Linux, addressing a critical vulnerability that could allow attackers to execute arbitrary code remotely. Users are strongly advised to update their browsers immediately to protect …

How to Enrich Alerts with Live Attack Data From 15K SOCs 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every SOC analyst knows the frustration. Your SIEM generates hundreds, sometimes thousands of alerts daily. Each alert demands attention, but with limited time and resources, how do you prioritize effectively? Investigating each alert in isolation leaves teams reactive, overwhelmed, and …

Microsoft September 2025 Patch Tuesday – 81 Vulnerabilities Fixed Including 22 RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released its September 2025 Patch Tuesday updates, addressing a total of 81 security vulnerabilities across its product suite. The security patches cover a wide range of software, including Windows, Microsoft Office, Azure, and SQL Server. Among the fixes …

Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salat Stealer has emerged as a pervasive threat targeting Windows endpoints with a focus on harvesting browser-stored credentials and cryptocurrency wallet data. First detected in August 2025, this Go-based infostealer leverages a range of evasion tactics, including UPX packing and …

FortiDDoS OS Command Injection Vulnerability Let Attackers Execute Unauthorized Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has disclosed a medium-severity vulnerability in its FortiDDoS-F product line that could allow a privileged attacker to execute unauthorized commands. Tracked as CVE-2024-45325, the flaw is an OS command injection vulnerability residing within the product’s command-line interface (CLI). The …

Beware of Phishing Email from Kimusky Hackers With Subject Spetember Tax Return Due Date Notice

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of phishing attacks purporting to originate from South Korea’s National Tax Service has emerged, leveraging familiar electronic document notifications to trick recipients into divulging their Naver credentials. Distributed on August 25, 2025, the email mimics the official …

Magento and Adobe SessionReaper Vulnerability Exposes Thousands of Online Stores to Automated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury has unveiled a sweeping sanctions campaign against a network of cyber scam centers across Southeast Asia that collectively stole more than ten billion dollars from American victims in 2024. These operations, often masquerading as …

Zoom Security Update – Patch for Multiple Vulnerabilities in Clients for Windows and macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom released a security update addressing multiple vulnerabilities in its software, including Zoom Workplace and various clients for Windows and macOS. The patches cover one high-severity flaw and several medium-severity issues, prompting a strong recommendation for users to update their …

How a Faulty Windows Driver Can Cause a System Crash and Blue Screen of Death

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent analysis of a Windows kernel-memory dump has provided a detailed look into a DRIVER_POWER_STATE_FAILURE, a critical error that results in a Blue Screen of Death (BSOD). The investigation reveals how a single malfunctioning driver can cause a system-wide …

New Cyber Attack Weaponizes DeskSoft to Deploy Malware Leveraging RDP Access to Execute Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber attack has emerged targeting organizations through a malicious impersonation of DeskSoft’s legitimate EarthTime application, deploying multiple malware families in a coordinated ransomware operation. The attack represents a concerning evolution in threat actor tactics, demonstrating how legitimate software …