New TEE.fail Attack Breaks Trusted Environments to Exfiltrate Secrets from Intel and AMD DDR5 Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A groundbreaking security vulnerability has emerged that fundamentally challenges the integrity of modern trusted execution environments across Intel and AMD server platforms. Researchers from Georgia Tech, Purdue University, and van …

AWS US-EAST-1 Region Experiences Delays in EC2 Instance Deployments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services encountered significant operational challenges in its US-EAST-1 region on October 28, 2025, with elevated latencies affecting EC2 instance launches and cascading issues across container orchestration services. The …

WordPress Plugin Vulnerability Exposes 7 Million Sites to XSS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical cross-site scripting (XSS) vulnerability has been discovered in the popular LiteSpeed Cache plugin for WordPress, affecting millions of websites worldwide. The vulnerability, tracked as CVE-2025-12450, poses a significant …

Hikvision Exploiter – An Automated Exploitation Toolkit Targeting Hikvision IP Cameras

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new open-source tool called HikvisionExploiter has emerged, designed to automate attacks on vulnerable Hikvision IP cameras. Released on GitHub in mid-2024 but gaining renewed attention amid 2025’s surge in …

10 Malicious npm Packages with Auto-Run Feature on Install Deploys Multi-Stage Credential Harvester

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The npm ecosystem faces a sophisticated new threat as ten malicious packages have emerged, each designed to automatically execute during installation and deploy a comprehensive credential harvesting operation. This attack …

PoC Exploit Released for BIND 9 Vulnerability that Let Attackers Forge DNS Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A public exploit code demonstrating how attackers could exploit CVE-2025-40778, a critical vulnerability in BIND 9 that enables DNS cache poisoning. The Internet Systems Consortium (ISC) initially disclosed this flaw …

Thousands of Exchange Servers in Germany Still Running with Out-of-Support Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Exchange servers in Germany are still running without security updates, just weeks after the official end of support for key versions. The Federal Office for Information Security (BSI) issued …

Chrome to Alert Users “Always Use Secure Connections” While Opening Public HTTP Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced a significant security initiative that will fundamentally change how Chrome handles unsecured web connections. Beginning with Chrome 154’s release in October 2026, the browser will enable the …

Windows Accessibility Flaw Allows Stealthy Persistence and Lateral Movement via Narrator DLL Hijack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent vulnerability related to DLL hijacking has been identified in the Narrator accessibility tool, which has been a significant concern over time. This flaw allows malicious actors to exploit …