New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged, targeting Indonesia’s most vulnerable digital citizens through a calculated exploitation of trust in the nation’s pension fund system. The malicious operation impersonates PT Dana …

Underground Ransomware Gang With New Tactics Against Organizations Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past year, the Underground ransomware gang has emerged as a formidable threat to organizations across diverse industries and geographies. First identified in July 2023, the group resurfaced in …

Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A widespread service issue is impacting Microsoft Teams users globally this Thursday, preventing many from opening embedded Microsoft Office documents within the collaboration platform. Reports began surfacing early this morning, …

28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day remote code execution (RCE) vulnerability, tracked as CVE-2025-7775, is affecting over 28,000 Citrix instances worldwide. The flaw is being actively exploited in the wild, prompting the U.S. …

PoC Exploit Released for CrushFTP 0-day Vulnerability (CVE-2025-54309)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A weaponized proof-of-concept exploit has been publicly released targeting CVE-2025-54309, a severe authentication bypass vulnerability affecting CrushFTP file transfer servers.  The flaw enables remote attackers to gain administrative privileges through …

How ClickFix and Multi-Stage Phishing Frameworks Are Breaking Enterprise Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 2025 has marked a significant evolution in cybercrime tactics, with threat actors deploying increasingly sophisticated phishing frameworks and social engineering techniques that are successfully bypassing traditional security defenses. Security …

IPFire Web-Based Firewall Interface Allows Authenticated Administrator to Inject Persistent JavaScript

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stored cross-site scripting (XSS) flaw identified in IPFire 2.29’s web-based firewall interface (firewall.cgi).  Tracked as CVE-2025-50975, the vulnerability allows any authenticated administrator to inject persistent JavaScript into firewall rule …

NVIDIA NeMo AI Curator Enables Code Execution and Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has issued a critical security bulletin addressing a high-severity vulnerability in its NeMo Curator platform that could allow attackers to execute malicious code and escalate privileges on affected systems.  …

CISA releases New ICS Advisories Surrounding Vulnerabilities and Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA released three significant Industrial Control Systems (ICS) advisories on August 26, 2025, alerting organizations to critical vulnerabilities affecting widely-deployed automation systems.  These advisories highlight severe security flaws across INVT …

Analysis of Apple’s ImageIO Zero-Day Vulnerability: Attacker Context and Historical iOS Zero-Click Similarities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has issued emergency security updates across its entire ecosystem to address CVE-2025-43300, a critical zero-day This represents the seventh zero-daymacOS devices. The vulnerability’s addition to CISA’s Known Exploited Vulnerabilities (KEV) catalog …