GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical deserialization flaw in GoAnywhere MFT’s License Servlet, tracked as CVE-2025-10035, has already been weaponized by the Storm-1175 group to execute the Medusa ransomware. The vulnerability affects GoAnywhere MFT …

Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has released a security advisory detailing a medium-severity vulnerability in the Kibana CrowdStrike Connector that could allow for the exposure of sensitive credentials. The flaw, tracked as CVE-2025-37728, affects …

CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent security advisory, adding Microsoft Windows privilege escalation vulnerability CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025.  The vulnerability affects the Microsoft …

OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim’s machine. The vulnerability is …

Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch …

13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 13-year-old critical remote code execution (RCE) vulnerability in Redis, dubbed RediShell, allows attackers to gain full access to the underlying host system. The flaw, tracked as CVE-2025-49844, was discovered …

Reemo Unveils Bastion+: A Scalable Solution for Global Privileged Access Management

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paris, France, October 6th, 2025, CyberNewsWire Reemo continues its mission to secure enterprise remote access and becomes the first French cybersecurity provider to protect all remote access within a single …

Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed responsibility for a significant data breach at Huawei Technologies, a multinational technology corporation based in China. The actor is reportedly attempting to sell what they …

Doctors Imaging Group Suffers Data Breach – 171800+ Users Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Doctors Imaging Group, a healthcare provider based in Florida, has reported a significant data breach that exposed the sensitive personal and medical information of over 171,800 individuals. The incident, classified …

Forensic-Timeliner – Windows Forensic Tool for DFIR Investigators

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Forensic-Timeliner, a Windows forensic tool for DFIR investigators, has released version 2.2, which offers enhanced automation and improved artifact support for digital forensics and incident response operations. This high-speed processing …