Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems. The flaw, tracked as CVE-2025-64740, has …

Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentication is completed. …

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security investigation reveals that 65% of prominent AI companies have leaked verified secrets on GitHub, exposing API keys, tokens, and sensitive credentials that could compromise their operations and …

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure default …

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses in traditional email security defenses by targeting the world’s two …

Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight two high-severity issues alongside medium-rated flaws, underscoring the ongoing challenges …

SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones, focusing on vulnerabilities that could enable remote code execution and …

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster tracked as UNC6485 has been weaponizing this flaw since August 2025 to …

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks. The …

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote Monitoring and Management platform. Two prominent ransomware groups, Medusa and …