Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as CVE-2025-68615, this security flaw allows remote attackers to trigger …

Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and potentially granting unauthorized access to VPNs and admin consoles. Fortinet’s …

Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced hardware-accelerated BitLocker, a significant security enhancement designed to eliminate performance bottlenecks caused by encryption on modern high-speed NVMe drives. The new technology addresses growing concerns about CPU …

Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November 2022, using advanced techniques to deliver the MgBot malware. The …

Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to look like legitimate security tools. The attacks began in November …

Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software and endpoint detection tools. The tool was posted on an …

Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication. The flaw resides in MongoDB’s zlib compression implementation and affects …

One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges our understanding of digital security. Unlike traditional attacks that require …

WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept exploits and gaming utilities. The malware targets users searching for …

Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000 IT systems across the agency and 10 of its 11 …