Threat Actors Allegedly Selling macOS 0-day LPE Exploit on Hacker Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as “skart7” is allegedly offering a zero-day Local Privilege Escalation (LPE) exploit targeting Apple’s macOS operating system for sale on a prominent hacker forum.  This development …

Iran’s Cyber Actors Attacking Global Airlines to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The breach of Tehran-based security contractor Amnban has ripped the cover off a multi-year espionage program that quietly burrowed into airline reservation systems across Africa, Europe, and the Middle East. …

Apache Jena Vulnerability Leads to Arbitrary File Access or Manipulation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache Jena has disclosed two significant security vulnerabilities affecting versions through 5.4.0, prompting an immediate upgrade recommendation to version 5.5.0.  Both CVE-2025-49656 and CVE-2025-50151, announced on July 21, 2025, represent …

UK Confirms Ban of Ransomware Payments to Public and Critical National Infrastructure Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK government has announced comprehensive measures to tackle ransomware attacks, with public sector organizations and critical national infrastructure operators facing an outright ban on paying ransom demands to cyber …

ETQ Reliance RCE Vulnerability Enables Full SYSTEM Access Just by Typing a Single Space

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in ETQ Reliance quality management software allows attackers to gain full administrative access by simply adding a single space character to a login attempt.  The flaw, tracked …

New Scanner Released to Detect SharePoint Servers Vulnerable to 0-Day Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source scanning tool has been released to identify SharePoint servers vulnerable to the critical zero-day exploit CVE-2025-53770.  The newly published scanner, available on GitHub, enables organizations to rapidly assess …

Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple security vulnerabilities affecting Sophos firewall products, with two enabling pre-authentication remote code execution that could allow attackers to compromise systems without valid credentials.  The vulnerabilities, tracked as CVE-2025-6704, CVE-2025-7624, …

Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Systems has issued a critical security advisory warning of multiple remote code execution vulnerabilities in its Identity Services Engine (ISE) that are being actively exploited by attackers in the …

UK Sanctions Russian APT 28 Hackers for Attacking Microsoft Cloud Service Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The UK Government has imposed sanctions on Russian military intelligence units and 18 individuals following the exposure of a sophisticated cyber espionage campaign targeting Microsoft cloud services.  The National Cyber …

New DCHSpy Android Malware Steals WhatsApp Data, Call Logs, Record Audio and Take Photos

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of DCHSpy Android surveillanceware, deployed by the Iranian cyber espionage group MuddyWater just one week after escalating tensions in the Israel-Iran conflict.  This malicious tool represents …