First Zero Click Attack Exploits MCP and Connected Popular AI Agents To Exfiltrate Data Silently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new zero-click attack dubbed Shadow Escape exploits the Model Context Protocol (MCP) to silently steal sensitive data via popular AI agents such as ChatGPT, Claude, and Gemini. This vulnerability, …

CISA Warns Of Critical Veeder-Root Vulnerabilities Let Attackers Execute System-level Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark advisory highlighting two severe vulnerabilities in Veeder-Root’s TLS4B Automatic Tank Gauge System, a critical tool used in fuel …

Windows Introduces Quick Memory Scan Feature During Restart After BSOD Crashes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is enhancing Windows 11’s stability with a new feature that prompts users for a quick memory diagnostic scan following blue screen of death (BSOD) incidents. This proactive tool aims …

OpenVPN Vulnerability Exposes Linux, macOS Systems to Script Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new vulnerability in early versions of OpenVPN has been disclosed, potentially allowing malicious servers to execute arbitrary commands on client machines. The flaw affects OpenVPN releases from 2.7_alpha1 to …

Apache Tomcat Security Vulnerabilities Expose Servers to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has highlighted critical flaws in Apache Tomcat, a widely used open-source Java servlet container that powers numerous web applications. On October 27, 2025, Apache disclosed two …

81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late 2025, a staggering 81% of broadband users were found to have never changed their router’s default administrative password, opening the door to significant malware risk. This widespread negligence …

iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The ‘shutdown.log’ file on Reboot

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of Pegasus and Predator spyware over the past several years has transformed the landscape of mobile device security. These advanced malware strains—deployed by sophisticated threat actors for surveillance …

nsKnox Launches Adaptive Payment Security™, Revolutionizing B2B Fraud Prevention by Solving the ‘Impossible Triangle’ of Speed, Certainty, and Effor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New York, New York, USA, October 27th, 2025, CyberNewsWire nsKnox, a leader in payment security, today announced the launch of Adaptive Payment Security, a groundbreaking enhancement to its PaymentKnox platform …

Ubiquiti UniFi Door Access App Vulnerability Exposes API Management Without Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ubiquiti’s UniFi Access application has been found vulnerable to a critical flaw that leaves its management API exposed without authentication. Discovered by Catchify Security, this issue allows malicious actors on …

Predatory Sparrow Group Attacking Critical Infrastructure to Destroy Data and Cause Disruption

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Predatory Sparrow has emerged as one of the most destructive cyber-sabotage groups targeting critical infrastructure across the Middle East, with operations focused primarily on Iranian and Syrian assets. The hacktivist …