Windows LPE Vulnerabilities via Kernel Drivers and Named Pipes Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are increasingly focusing on privilege escalation attacks through two primary Windows attack surfaces: kernel drivers and named pipes. These vectors exploit fundamental trust boundary weaknesses between the user …

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including …

OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has rolled out a critical security update to ChatGPT Atlas, its browser-based AI agent, introducing advanced defenses against prompt injection attacks. The update marks a significant step in protecting …

Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Condé Nast, the parent company. The threat actor “Lovely” claims this is just …

MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw …

Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The chaos surrounding Ubisoft escalated significantly today as the first group of hackers, previously known for silent exploits, initiated a highly visible and disruptive takeover of Rainbow Six Siege servers. …

87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, …

Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit dubbed “mongobleed” for CVE-2025-14847, a critical unauthenticated memory leak vulnerability in MongoDB’s zlib decompression handling. Dubbed by its creator Joe Desimone as a way to bleed …

TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities in TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), formerly part of 1E Client. Affecting Windows versions before 25.11 and select older branches, the flaws stem from improper …

M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse session tokens from active users. Potentially gaining unauthorized access to sensitive document management systems. The flaw, …