Critical Tableau Server Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Tableau Server could enable attackers to upload and execute malicious files, potentially leading to complete system compromise.  The vulnerability, tracked as CVE-2025-26496 with a CVSS …

NIST Publish ‘Lightweight Cryptography’ Standard To Protect IoT Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Institute of Standards and Technology (NIST) has officially released NIST Special Publication 800-232, establishing the Ascon family of algorithms as the new standard for lightweight cryptography designed specifically …

Microsoft Copilot Agent Policy Let Any Users Access AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Shortly after the May 2025 rollout of 107 Copilot Agents in Microsoft 365 tenants, security specialists discovered that the “Data Access” restriction meant to block agent availability is being ignored.  …

New macOS Installer Promising Lightning-fast Data Exfiltration Advertised on Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered macOS stealer, dubbed Mac.c, has surfaced on darknet forums, offering lightning-fast data exfiltration for just $1,500 per month. Developed by the threat actor “mentalpositive,” Mac.c is advertised …

PoC Exploit & Vulnerability Analysis Released for Apple 0-Day RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A detailed proof-of-concept exploit and comprehensive vulnerability analysis have been released for CVE-2025-43300, a critical zero-click remote code execution flaw affecting Apple’s image processing infrastructure.  The vulnerability, discovered in Apple’s …

Hackers Leverage SendGrid in Recent Attack to Harvest Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated credential harvesting campaign has emerged, exploiting the trusted reputation of SendGrid to deliver phishing emails that successfully bypass traditional email security gateways. The attack leverages SendGrid’s legitimate cloud-based …

KorPlug Malware Unmasked – TTPs, Control Flow, IOCs Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware strain known as KorPlug has emerged as a significant threat in the cybersecurity landscape, employing advanced obfuscation techniques to evade detection and complicate analysis efforts. This malware …

New Microsoft 365 Admin Feature Let Admins Control Link Creation Policies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is rolling out a significant new administrative control feature in mid-September 2025 that will enable IT administrators to manage organization-wide sharing permissions for user-built Copilot agents.  The feature addresses …