Cybersecurity News Weekly Newsletter – Fortinet, Chrome 0-Day Flaws, Cloudflare Outage and Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of the Cybersecurity News Weekly Newsletter, where we analyze the critical incidents defining the current threat landscape. If this week has taught us anything, it …

Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels. The flaw, categorized as an authentication bypass vulnerability, poses an …

Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a significant disruption affecting Windows 11 version 24H2 users, specifically after installing the cumulative update KB5062553 released in July 2025. The issue primarily affects environments using …

ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce. The …

Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code …

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of …

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective. The incident, which came to light late Thursday …

AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus …

Xillen Stealer With New Advanced Features Evade AI Detection and Steal Sensitive Data from Password Managers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Xillen Stealer, a sophisticated Python-based information stealer, has emerged as a significant threat in the cybercriminal landscape. Originally identified by Cyfirma in September 2025, this cross-platform malware has recently evolved …