New Vulnerabilities in Bluetooth Headphones Let Hackers Hijack Connected Smartphone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have disclosed critical vulnerabilities affecting widely used Bluetooth headphones and earbuds that could allow attackers to eavesdrop on conversations, steal sensitive data, and even hijack connected smartphones. The flaws, identified as CVE-2025-20700, CVE-2025-20701, and CVE-2025-20702, impact devices powered …

Hacktivist Proxy Operations Emerge as a Repeatable Model of Geopolitical Cyber Pressure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new form of cyber disruption is reshaping the landscape of modern conflict. Hacktivist groups are increasingly operating as strategic instruments of state pressure, launching coordinated attacks that align perfectly with geopolitical events such as sanctions announcements and military aid …

Hacker Threw MacBook in River to Erase Evidence in Coupang Data Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a desperate attempt to cover his tracks, the hacker behind Coupang’s massive personal data leak hurled his MacBook Air into a nearby river, only for company investigators to fish it out days later. This cinematic twist emerged as South …

Windows LPE Vulnerabilities via Kernel Drivers and Named Pipes Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers are increasingly focusing on privilege escalation attacks through two primary Windows attack surfaces: kernel drivers and named pipes. These vectors exploit fundamental trust boundary weaknesses between the user and kernel modes. Enabling attackers to escalate from standard user …

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including credentials, session tokens, and personally identifiable information, directly from server …

OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has rolled out a critical security update to ChatGPT Atlas, its browser-based AI agent, introducing advanced defenses against prompt injection attacks. The update marks a significant step in protecting users from emerging adversarial threats targeting agentic AI systems. What …

Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Condé Nast, the parent company. The threat actor “Lovely” claims this is just the start, promising to release up to 40 million more …

MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw affecting multiple supported and legacy server versions that allows unauthenticated …

Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The chaos surrounding Ubisoft escalated significantly today as the first group of hackers, previously known for silent exploits, initiated a highly visible and disruptive takeover of Rainbow Six Siege servers. Players worldwide are reporting a massive influx of in-game currency, …

87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score …