NCSC Warns of Oracle E-Business Suite 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NCSC has issued an urgent warning regarding a critical zero-day flaw in Oracle E-Business Suite (EBS) that is currently being exploited in the wild.  Tracked as CVE-2025-61882, the vulnerability resides …

Zabbix Agent and Agent 2 for Windows Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Zabbix Agent and Agent 2 for Windows that allows attackers with local system access to escalate their privileges through DLL injection attacks.  …

Google Chrome RCE Vulnerability Details Released Along with Exploit Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have published the full technical details and exploit code for a critical remote code execution (RCE) vulnerability in Google Chrome’s V8 JavaScript engine.  Tracked internally as a WebAssembly type …

Microsoft Teams Set to Introduce Highly Anticipated Multitasking Functionality

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is set to roll out a highly anticipated multitasking feature for its Teams platform, which will allow users to open channels in separate windows. This long-awaited update, scheduled for …

Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the Gemini Command-Line Interface (CLI). This new open-source package integrates …

PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A publicly available proof-of-concept (PoC) exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) flaw in the Sudo utility that can grant root access under specific configurations.  Security …

Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that …

Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique uncovered where threat actors abuse Amazon Web Services‘ X-Ray distributed tracing service to establish covert command and control (C2) communications, demonstrating how legitimate cloud infrastructure can be …

QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QNAP has released a security advisory detailing a vulnerability in its NetBak Replicator utility that could allow local attackers to execute unauthorized code. The flaw, identified as CVE-2025-57714, has been …

How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PsExec represents one of the most contradictory tools in the cybersecurity landscape, a legitimate system administration utility that has become a cornerstone of malicious lateral movement campaigns. Recent threat intelligence …