2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web services at risk. On December 3, React disclosed CVE-2025-55182, a …

Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the aswSnx kernel driver. The flaws, now tracked collectively as CVE-2025-13032, …

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Madison, United States, December 5th, 2025, CyberNewsWire Sprocket Security is proud to announce that it has once again been recognized by G2 for “High Performer,” “Best Support,” and “Easiest to …

Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Torrance, California, USA, December 5th, 2025, CyberNewsWire Criminal IP will host a live webinar on December 16 at 11:00 AM Pacific Time (PT), focusing on the shift in cyberattack strategies. …

Netflix Acquires Warner Bros. Studios and HBO in Landmark $82.7 Billion Megadeal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Netflix has struck a transformative deal to acquire Warner Bros. studios, HBO, and HBO Max from Warner Bros. Discovery (WBD) in a cash-and-stock transaction valued at $82.7 billion. The move …

Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are actively spreading CoinMiner malware through USB drives, targeting workstations across South Korea to mine Monero cryptocurrency. This ongoing campaign uses deceptive shortcut files and hidden folders to trick …

MuddyWater Hackers Using UDPGangster Backdoor to Attack Windows Systems Evading Network Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber threat has emerged targeting Windows systems across multiple countries in the Middle East. UDPGangster, a UDP-based backdoor, represents a dangerous new weapon in the arsenal of the …

Cloudflare Outage Traced to Emergency React2Shell Patch Deployment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare’s global network suffered a brief but widespread disruption this morning, lasting approximately 25 minutes, due to an internal change in its Web Application Firewall (WAF) designed to counter a …

AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent privilege escalation technique in AWS that allows attackers with limited permissions to execute code under higher-privileged execution roles on EC2 instances and SageMaker notebook instances. First documented by …

Russian Hackers Spoof European Events in Targeted Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian threat actors are running a new wave of phishing campaigns that spoof major European security events to quietly steal cloud credentials. Invitations that look legitimate, often tied to conferences …