Cybersecurity News Weekly Newsletter – EY Data Leak, Bind 9, Chrome Vulnerability, and Aardvar ChatGPT Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week’s cybersecurity roundup highlights escalating threats from misconfigurations, software flaws, and advanced malware. Key incidents demand immediate attention from IT teams and executives. ISC patched CVE-2025-5470 in BIND 9 …

New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An upgraded release of tool EDR-Redir V2, designed to evade Endpoint Detection and Response (EDR) systems by exploiting Windows bind link technology in a novel way. According to the researcher …

OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled Aardvark, an autonomous AI agent powered by its cutting-edge GPT-5 model, designed to detect software vulnerabilities and automatically propose fixes. This tool aims to entrust developers and …

Agent Session Smuggling: How Malicious AI Hijacks Victim Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a sophisticated attack technique that exploits the trust relationships built into AI agent communication systems. The attack, termed agent session smuggling, allows a malicious AI agent …

Akira Ransomware Allegedly Claims Theft of 23GB in Apache OpenOffice Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Akira ransomware group announced on October 29, 2025, that it successfully breached the systems of Apache OpenOffice, exfiltrating a staggering 23 gigabytes of sensitive corporate data. The group, …

CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a critical use-after-free vulnerability in the Linux kernel, tracked as CVE-2024-1086. This vulnerability, hidden within the …

Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals and state-sponsored actors are ramping up attacks on unpatched Cisco IOS XE devices across Australia, deploying a persistent Lua-based web shell known as BADCANDY to maintain unauthorized access. This …

Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Server Update Services (WSUS) vulnerability actively exploited in the wild. Criminals are using this vulnerability to steal sensitive data from organizations in various industries. The vulnerability, tracked as CVE-2025-59287, …

Stolen Credentials and Valid Account Abuse Fuel the Financially Motivated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Throughout the first half of 2025, financially motivated threat actors have shifted their approach to intrusions, abandoning traditional implant-heavy methods in favor of a more cost-effective strategy. Rather than deploying …

Beware of Malicious ChatGPT Apps That Records Users Action and Steals Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The explosive growth of artificial intelligence has created an unexpected security threat as cybercriminals exploit ChatGPT’s popularity through counterfeit mobile applications. Recent security research uncovered sophisticated malicious apps masquerading as …