Formbricks Signature Verification Vulnerability Let Attackers Reset User Passwords Without Authorization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw discovered in Formbricks, an open-source experience management platform, demonstrates how missing JWT signature verification can lead to complete account takeovers.  The vulnerability tracked as CVE-2025-59934 affects …

Windows Heap Exploitation Vulnerability With Record’s Size Field Leads to Arbitrary R/W

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows heap management demonstrates how improper handling of record-size fields enables arbitrary memory read and write operations.  Suraj Malhotra shared a detailed exploitation technique leveraging the …

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish robust command and control infrastructure. These publicly rentable subdomain services, …

Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered DLL hijacking vulnerability in Notepad++, the popular source code editor, could allow attackers to execute arbitrary code on a victim’s machine. Tracked as CVE-2025-56383, the flaw exists …

Cybersecurity Newsletter Weekly – Chrome 0-Day, 22.2 Tbps DDOS Attack, Kali Linux Release, Cisco IOS 0-Day and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity was marked by a relentless pace of critical disclosures and unprecedented attack volumes, underscoring the escalating challenges facing defenders. At the forefront was Google’s emergency patch …

Google Project Zero Details ASLR Bypass on Apple Devices Using NSDictionary Serialization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Google Project Zero researcher has detailed a novel technique for remotely leaking memory addresses on Apple’s macOS and iOS. This method can bypass a key security feature, Address Space …

Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search engine results and abused code-signing certificates to deliver the Oyster backdoor malware. The …

Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has emerged in Apache Airflow 3.0.3, exposing sensitive connection information to users with only read permissions. The vulnerability, tracked as CVE-2025-54831 and classified as “important” severity, …

Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercriminal alliance between malware operators and covert North Korean IT workers has emerged as a significant threat to corporate organizations worldwide. This hybrid operation, known as DeceptiveDevelopment, represents …