Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in the widely used npm package expr-eval, potentially exposing AI and natural language processing applications to remote code execution attacks. The vulnerability, tracked …

LangGraph Vulnerability Allows Malicious Python Code Execution During Deserialization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability has been discovered in LangGraph’s checkpoint serialization system. The flaw CVE-2025-64439 affects versions of langgraph-checkpoint before 3.0. It allows attackers to execute arbitrary Python …

Fired Intel Engineer Stolen 18,000 Files, Many of which Were Classified as “Top Secret”

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Intel has filed a federal lawsuit against a former employee accused of downloading thousands of classified documents shortly after being terminated, raising serious concerns about corporate data security and insider …

New Report Warns of Threat Actors Actively Adopting AI Platforms to Attack Manufacturing Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The manufacturing sector faces an escalating threat landscape as cybercriminals increasingly exploit cloud-based platforms and artificial intelligence services to conduct sophisticated attacks. A comprehensive analysis by Netskope Threat Labs reveals …

Google’s Gemini Deep Research Tool Gains Access to Gmail, Chat, and Drive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has expanded its Gemini AI model’s Deep Research feature to pull data directly from users’ Gmail, Google Drive, and Google Chat accounts. Announced today, this update allows the tool …

10 Popular Black Friday Scams – How to Detect the Red Flags and Protect your wallet and Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Black Friday 2025 represents the most dangerous shopping season in cybercrime history, with fraudsters leveraging artificial intelligence, deepfake technology, and sophisticated social engineering tactics to target millions of consumers globally. …

MAD-CAT Meow Attack Tool to Simulate Real-World Data Corruption Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MAD-CAT (Meow Attack Data Corruption Automation Tool) targets MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, exactly the systems hit in the original wave. This persistent threat inspired security researcher …

Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms. These flaws could allow attackers to escape container isolation and gain root access to host …

Monsta web-based FTP Remote Code Execution Vulnerability Exploited

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide. The flaw, now tracked as CVE-2025-34299, affects multiple versions of …

HackGPT: AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need for effective vulnerability assessments. The platform supports multi-model AI, including …