PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. Dubbed “NVIDIAScape” and tracked as CVE-2025-23266, this flaw carries a maximum CVSS score of 9.0, representing one of the most …

New 7-Zip Vulnerability Enables Malicious RAR5 File to Crash Your System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical memory corruption vulnerability in the popular file archiver 7-Zip has been discovered that allows attackers to trigger denial of service conditions by crafting malicious RAR5 archive files. The vulnerability, tracked as CVE-2025-53816 and designated GHSL-2025-058, affects all versions …

Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It’s been a busy seven days for security alerts. Google is addressing another actively exploited zero-day in Chrome, and VMware has rolled out key patches for its own set of vulnerabilities. We’ll also break down the methods behind a new …

Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.  The vulnerabilities, identified as CVE-2025-6023 and CVE-2025-6197, affect multiple versions of Grafana, including 12.0.x, 11.6.x, 11.5.x, 11.4.x, and 11.3.x branches.  Both …

SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed “ToolShell,” enabling attackers to gain complete remote control over vulnerable systems without authentication. Eye Security, a Dutch cybersecurity firm, identified the active …

Snake Keylogger Evades Windows Defender and Scheduled Tasks to Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting Turkish defense and aerospace enterprises has emerged, delivering a highly evasive variant of the Snake Keylogger malware through fraudulent emails impersonating TUSAŞ (Turkish Aerospace Industries). The malicious campaign distributes files disguised as contractual documents, specifically …

Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese threat actor campaign has emerged as one of the most persistent malware distribution operations targeting Chinese-speaking communities worldwide. Since June 2023, this ongoing campaign has established an extensive infrastructure comprising more than 2,800 malicious domains specifically designed …

New Veeam Themed Phishing Attack Using Weaponized Wav File to Attack users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting organizations has emerged, exploiting the trusted reputation of Veeam Software through weaponized WAV audio files delivered via email. The attack represents an evolution in social engineering tactics, combining traditional phishing techniques with audio-based deception to …

New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day flaw in the CrushFTP managed file-transfer platform was confirmed after vendor and threat-intelligence sources confirmed active exploitation beginning on 18 July 2025 at 09:00 CST. Tracked as CVE-2025-54309, the bug allows unauthenticated attackers to obtain full administrative …

New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign dubbed “Scanception” has emerged as a significant threat to enterprise security, leveraging QR codes embedded in PDF attachments to bypass traditional email security measures and harvest user credentials. The attack represents a concerning evolution in social …