CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177).  This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor …

PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities.  The flaw …

New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide. First detected in late August 2025, …

Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes.  Originally marketed as an offensive security …

AI-Powered Cybersecurity Tools Can Be Turned Against Themselves Through Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI-powered cybersecurity tools can be turned against themselves through prompt injection attacks, allowing adversaries to hijack automated agents and gain unauthorized system access. Security researchers Víctor Mayoral-Vilches & Per Mannermaa …

Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company’s Salesforce instance. The breach was part of a wider supply chain …

ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability discovered in ESPHome’s web server component has exposed thousands of smart home devices to unauthorized access, effectively nullifying basic authentication protections on ESP-IDF platform implementations. The …

Google Confirms That Claims of Major Gmail Security Warning are False

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially debunked widespread reports claiming the company issued a major security warning to Gmail users, clarifying that such claims are entirely false. The technology giant addressed the misinformation …

New Phishing Attack Via OneDrive Attacking C-level Employees for Corporate Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spear-phishing campaign has emerged targeting senior executives and C-suite personnel across multiple industries, leveraging Microsoft OneDrive as the primary attack vector. The campaign utilizes carefully crafted emails masquerading …

New Report on Commercial Spyware Vendors Detailing Their Targets and Infection Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Commercial surveillance vendors have evolved from niche technology suppliers into a sophisticated multi-billion-dollar ecosystem that poses unprecedented threats to journalists, activists, and civil society members worldwide. A comprehensive new report …