Kimsuky Hackers Via Weaponized LNK File Abuses GitHub for Malware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The North Korea-backed APT group Kimsuky has escalated its cyber operations by weaponizing GitHub repositories for malware delivery and data exfiltration, marking a sophisticated evolution in their attack methodology. This …

Apple CarPlay Exploited To Gain Root Access By Executing Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At the recent DefCon security conference, researchers demonstrated a critical exploit chain that allows attackers to gain root access on vehicle infotainment systems by targeting Apple CarPlay. The multi-stage attack, …

New Gentlemen Ransomware Leverages Legitimate Drivers, Group Policies to Infiltrate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security researchers have observed a surge in activity by a previously undocumented ransomware group known as The Gentlemen. This threat actor has rapidly distinguished itself through the …

GitLab Patches Multiple Vulnerabilities That Enables Denial Of Service and SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released urgent security patches for its Community (CE) and Enterprise (EE) editions, addressing multiple vulnerabilities, including two high-severity flaws that could lead to Server-Side Request Forgery (SSRF) and …

Top 10 Best Mobile Application Penetration Testing Companies in 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-quality mobile application penetration testing company is essential for businesses that want to safeguard their digital assets and user data. These specialized firms employ ethical hackers who simulate real-world …

Google Drive Desktop for Windows Vulnerability Grants Full Access to Another User’s Drive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been found in the Google Drive Desktop application for Windows. It allows a logged-in user on a shared machine to access another user’s Drive files completely …

Microsoft Warns of Active Directory Domain Services Vulnerability, Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an updated warning for a critical security vulnerability in Active Directory Domain Services, tracked as CVE-2025-21293. This flaw could permit an attacker who has already gained initial …

Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were …

HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of …

Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophos has resolved an authentication bypass vulnerability in its AP6 Series Wireless Access Points that could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security …