AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as …

NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the …

Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security breach has compromised Microsoft’s PlayReady Digital Rights Management (DRM) system, exposing critical certificates that protect premium streaming content across major platforms including Netflix, Amazon Prime Video, and …

Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity landscape continues to evolve as threat actors develop increasingly sophisticated methods to compromise Windows systems. A new ransomware variant known as Interlock has emerged as a significant threat, …

APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems, signaling a …

Cybersecurity News Recap – Chrome, Gemini Vulnerabilities, Linux Malware, and Man-in-the-Prompt Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of Cybersecurity News Recap! In this issue, we bring you the latest updates and critical developments across the threat landscape. Stay ahead of risks with key …

New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Linux backdoor dubbed Plague has emerged as an unprecedented threat to enterprise security, evading detection across all major antivirus engines while establishing persistent SSH access through manipulation of …

SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected zero-day vulnerability in SonicWall firewall devices that the Akira ransomware group is actively exploiting. The flaw allows attackers to gain initial access to corporate networks through SonicWall’s SSL …

Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages …

SafePay Ransomware Infected 260+ Victims Across Multiple Countries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware threat has emerged as one of the most aggressive cybercriminal operations of 2025, with SafePay ransomware claiming responsibility for over 265 successful attacks spanning multiple continents. The …