CISA Adds Critical React2Shell Vulnerability to KEV Catalog Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability affecting Meta React Server Components has been added to the Known Exploited Vulnerabilities catalog, signalling widespread active exploitation by CISA. Tracked as CVE-2025-55182, this remote code execution …

Critical Cal.com Vulnerability Let Attackers Bypass Authentication Via Fake TOTP Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe authentication bypass vulnerability has been discovered in cal.com, the popular open-source scheduling platform. Allowing attackers to gain unauthorized access to user accounts by submitting fake TOTP codes. According …

US Accounts for 44% of Cyber Attacks; Financial Gain Targets Public Administration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United States continues to face an unprecedented surge in cyber threats, accounting for nearly half of all documented cyber attacks globally between 2024 and 2025. Recent data from the …

The ‘Kitten’ Project – Hacktivist Groups Carrying Out Attacks Targeting Israel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Kitten Project has emerged as a coordinated hacktivist platform operating at the intersection of activism and technical operations. This initiative represents a shift in how cyber-focused groups organize their …

LOLPROX Exposes Hidden Exploitation Paths that Can Enable Stealthy Hypervisor Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Proxmox Virtual Environment has become a popular choice for organizations building private cloud infrastructure and virtual machine management systems. However, a new analysis reveals significant security gaps in how the …

Hackers Compromising Developers with Malicious VS Code, Cursor AI Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The developer tools used by millions of programmers worldwide have become a prime target for attackers seeking to compromise entire organizations. Visual Studio Code and AI-powered IDEs like Cursor AI, …

Critical WatchGuard Firebox Vulnerabilities Let Attackers Bypass Integrity Checks and Inject Malicious Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security alerts have been issued for Firebox firewall devices due to serious ten vulnerabilities. The vulnerabilities in WatchGuard, disclosed on December 4, 2025, span multiple severity levels and attack …

OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The OceanLotus hacker group, widely tracked as APT32, has initiated a highly targeted surveillance campaign aimed at China’s “Xinchuang” IT ecosystem. This strategic pivot focuses on compromising indigenized domestic hardware …

Indonesia’s Gambling Ecosystem Exposed With Indicators of National-Level Cyber Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cybercrime infrastructure operating for over fourteen years has been dismantled through extensive research into Indonesia’s illegal gambling networks. Security researchers have uncovered a sprawling ecosystem spanning hundreds of …

Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jack, a Solana enthusiast using the Phantom wallet, fell victim to a sophisticated crypto drainer scam that wiped out $9,000 from his wallet almost instantly. He informed Cybersecurity News that …