HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault in early August 2025, the widely adopted secrets management solution. These flaws, spanning authentication bypasses, policy enforcement inconsistencies, …

1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 1.2 million internet-connected healthcare devices and systems with exposure that endanger patient data shown in new research by European cybersecurity company Modat. Global findings showing Top 10 Regions (most results are …

HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme …

Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack method exploits Google’s Gemini AI assistant through seemingly innocent calendar invitations and emails.  The attack, dubbed “Targeted Promptware Attacks,” demonstrates how indirect prompt injection can compromise users’ …

Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and …

New Microsoft Exchange Server Vulnerability Enables Attackers to Gain Admin Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Exchange Server hybrid deployments has been disclosed, allowing attackers with on-premises administrative access to escalate privileges to cloud environments without easily detectable traces. The …

Akira and Lynx Ransomware Attacking Managed Service Providers With Stolen Login Credential and Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two sophisticated ransomware operations have emerged as significant threats to managed service providers (MSPs) and small businesses, with the Akira and Lynx groups deploying advanced attack techniques that combine stolen …

Lazarus Hackers Trick Users To Believe Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a new social engineering campaign attributed to North Korea’s Lazarus Group in recent weeks that leverages fake camera and microphone errors to force targets into running …

Threat Actors Weaponize Smart Contracts to Drain User Crypto Wallets of More Than $900k

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated campaign uncovered in early 2024, cybercriminals have begun distributing malicious Ethereum smart contracts masquerading as lucrative trading bots. These weaponized contracts leverage Web3 development platforms such as …

Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has emerged targeting Windows users through a deceptive malware variant known as ToneShell, which masquerades as the legitimate Google Chrome browser. The advanced persistent threat …