New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide. CVE-2025-32463 targets …

Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 …

Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer …

Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations. The attack exploits the widespread trust users place …

Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital …

Hackers Can Bypass OpenAI Guardrails Using a Simple Prompt Injection Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI’s newly launched Guardrails framework, designed to enhance AI safety by detecting harmful behaviors, has been swiftly compromised by researchers using basic prompt injection methods. Released on October 6, 2025, …

Axis Communications Vulnerability Exposes Azure Storage Account Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Axis Communications’ Autodesk Revit plugin has exposed Azure Storage Account credentials, creating significant security risks for customers and potentially enabling supply chain attacks targeting the architecture …

Hackers Leveraging Microsoft Edge Internet Explorer Mode to Gain Access to Users’ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape witnessed a concerning development as threat actors discovered a novel attack vector targeting Microsoft Edge’s Internet Explorer mode functionality. This sophisticated campaign emerged in August 2025, exploiting …

North Korean Hackers Attacking Developers with 338 Malicious npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean state-sponsored threat actors have intensified their supply chain attacks against software developers through a sophisticated campaign dubbed “Contagious Interview,” deploying 338 malicious npm packages that have accumulated over …

New WhatsApp Worm Attacks Users with Banking Malware to Users Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have identified a sophisticated malware campaign that exploits WhatsApp’s messaging platform to deploy banking trojans targeting Brazilian financial institutions and cryptocurrency exchanges. The self-propagating worm, which emerged on …