ETQ Reliance RCE Vulnerability Enables Full SYSTEM Access Just by Typing a Single Space

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in ETQ Reliance quality management software allows attackers to gain full administrative access by simply adding a single space character to a login attempt.  The flaw, tracked …

New Scanner Released to Detect SharePoint Servers Vulnerable to 0-Day Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source scanning tool has been released to identify SharePoint servers vulnerable to the critical zero-day exploit CVE-2025-53770.  The newly published scanner, available on GitHub, enables organizations to rapidly assess …

Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple security vulnerabilities affecting Sophos firewall products, with two enabling pre-authentication remote code execution that could allow attackers to compromise systems without valid credentials.  The vulnerabilities, tracked as CVE-2025-6704, CVE-2025-7624, …

Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Systems has issued a critical security advisory warning of multiple remote code execution vulnerabilities in its Identity Services Engine (ISE) that are being actively exploited by attackers in the …

UK Sanctions Russian APT 28 Hackers for Attacking Microsoft Cloud Service Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK Government has imposed sanctions on Russian military intelligence units and 18 individuals following the exposure of a sophisticated cyber espionage campaign targeting Microsoft cloud services.  The National Cyber …

New DCHSpy Android Malware Steals WhatsApp Data, Call Logs, Record Audio and Take Photos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of DCHSpy Android surveillanceware, deployed by the Iranian cyber espionage group MuddyWater just one week after escalating tensions in the Israel-Iran conflict.  This malicious tool represents …

ExpressVPN Windows Client Vulnerability Exposes Users Real IP Addresses With RDP Connection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in ExpressVPN Windows desktop application that could expose users’ real IP addresses when using Remote Desktop Protocol (RDP) connections.  The flaw, discovered through the company’s bug …

Threat Actors Combine Android Malware With Click Fraud Apps to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fresh wave of malicious Android Package Kit (APK) files is weaving together two of cybercrime’s most reliable revenue streams—click-fraud advertising and credential theft—into a single, adaptable threat that has …

GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware threat has emerged from the cybercriminal underground, targeting organizations across multiple operating systems with advanced cross-platform capabilities. In June 2025, a ransomware actor operating under the …

Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark Foundation has announced the availability of Wireshark 4.4.8, the latest maintenance release of the world’s most widely used network-protocol analyzer. Although the update does not introduce brand-new protocols, it …