Microsoft November 2025 Patch Tuesday – 63 Vulnerabilities, Including 1 Zero-Day Fixed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft rolled out its November 2025 Patch Tuesday security updates today, addressing 63 vulnerabilities across its product and service ecosystem. Among these, one zero-day flaw has already been exploited in …

Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has rolled out Firefox 145, addressing a series of high-severity vulnerabilities that could allow attackers to execute arbitrary code on users’ systems. Announced on November 11, 2025, the release …

Researchers Uncover the Strong Links Between Maverick and Coyote Banking Malwares

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers from CyberProof have discovered significant connections between two advanced banking trojans targeting Brazilian users and financial institutions. The Maverick banking malware, identified through suspicious file downloads via WhatsApp, …

New VanHelsing Ransomware RaaS Model Attacking Windows, Linux, BSD, ARM, and ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VanHelsing has emerged as a sophisticated ransomware-as-a-service operation that fundamentally changes the threat landscape for organizations worldwide. First observed on March 7, 2025, this multi-platform locker represents a significant escalation …

Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has rolled out security updates for its Endpoint Manager product, addressing three high-severity vulnerabilities that could let authenticated local attackers write arbitrary files anywhere on the system disk. The …

Android Remote Data-Wipe Malware Attacking Users Leveraging Google’s Find Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated remote data-wipe attack targeting Android devices has emerged, exploiting Google’s Find Hub service to execute destructive operations on smartphones and tablets across South Korea. This campaign represents the …

Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Synology has released an urgent security update addressing a critical remote code execution vulnerability in BeeStation OS that allows unauthenticated attackers to execute arbitrary code on affected devices. The vulnerability, …

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted, plain-text nature of calendar invitations to …

Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages. The threat landscape shifted on November 5, 2025, when researchers identified nine malicious NuGet packages …