LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LockBit 5.0 key infrastructure exposed, revealing the IP address 205.185.116.233, and the domain karma0.xyz is hosting the ransomware group’s latest leak site. According to researcher Rakesh Krishnan, hosted under AS53667 …

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In an escalating campaign targeting remote access infrastructure, threat actors have initiated active exploitation attempts against Palo Alto Networks’ GlobalProtect VPN portals. GrayNoise tracking activity report scans and exploitation efforts …

New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous new Android banking malware named FvncBot was first observed on November 25, 2025. This malicious tool is designed to steal sensitive financial information by logging keystrokes, recording screens, and injecting …

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for …

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows attackers to inject malicious prompts via untrusted user inputs like …

2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web services at risk. On December 3, React disclosed CVE-2025-55182, a …

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the aswSnx kernel driver. The flaws, now tracked collectively as CVE-2025-13032, …

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Madison, United States, December 5th, 2025, CyberNewsWire Sprocket Security is proud to announce that it has once again been recognized by G2 for “High Performer,” “Best Support,” and “Easiest to …

Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, California, USA, December 5th, 2025, CyberNewsWire Criminal IP will host a live webinar on December 16 at 11:00 AM Pacific Time (PT), focusing on the shift in cyberattack strategies. …

Netflix Acquires Warner Bros. Studios and HBO in Landmark $82.7 Billion Megadeal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Netflix has struck a transformative deal to acquire Warner Bros. studios, HBO, and HBO Max from Warner Bros. Discovery (WBD) in a cash-and-stock transaction valued at $82.7 billion. The move …