GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security patches on December 10, 2025, addressing ten significant vulnerabilities across its Community Edition and Enterprise Edition platforms. GitLab has released updated versions 18.6.2, 18.5.4, and 18.4.6 to address multiple high-severity security issues. High-Severity Threats Identified Four vulnerabilities received …

High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Patches released by Jenkins address a significant denial-of-service (DoS) vulnerability affecting millions of organizations. That rely on the popular automation server for continuous integration and deployment pipelines. A high-severity vulnerability in Jenkins versions 2.540 and earlier (LTS 2.528.2 and earlier). …

Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new AMOS InfoStealer campaign is abusing trust in ChatGPT to infect Mac devices under the guise of simple troubleshooting help. Victims search for a fix to a sound problem, click a sponsored ChatGPT result, and are shown what looks …

Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a significant threat targeting developers through the VS Code Marketplace. A coordinated campaign involving 19 malicious extensions has been actively infiltrating the platform, with the attack remaining undetected since February 2025. These deceptive extensions carry hidden …

Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems. The vulnerability, tracked as CVE-2025-62468, was assigned an Important severity rating and released on December 9, 2025. …

Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code and bypass essential security features. Adobe issued security bulletin APSB25-119 on December 9, 2025, with a priority rating of 3, affecting both …

Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an urgent security update for the Chrome browser to address a high-severity zero-day vulnerability that is currently being exploited in the wild. This emergency patch is part of the latest Stable channel update, bringing the version to …

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers to hijack administrator sessions without authentication. The vulnerability, identified as CVE-2025-10573, has been assigned a CVSS score of 9.6 and …

Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to their scanning methodologies, researchers have identified a massive attack surface comprising over 165,000 …

New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for financial fraud. This toolkit, observed by Varonis, allows threat actors, even those with minimal technical skill, to spin up pixel-perfect …