New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Less than a week after addressing a critical Remote Code Execution (RCE) vulnerability, the React team has disclosed three additional security flaws affecting React Server Components (RSC). Security researchers discovered these new issues while attempting to bypass the mitigations for …

GitHub Down! Developers Frustrated by ‘No Server Available’ Message

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitHub is experiencing user-reported outages, with many developers greeted by a prominent error featuring the platform’s unicorn mascot and the message “No server is currently available to service your request.”​ Numerous users across forums and monitoring sites have shared screenshots …

Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular text editor Notepad++ has addressed a severe security weakness in its update mechanism that could allow attackers to hijack network traffic and push malicious executables to users under the guise of legitimate updates. Security researchers recently observed suspicious …

Gogs 0-Day Vulnerability Exploited in the Wild to Hack 700+ Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Gogs, a widely used self-hosted Git service, is currently being exploited in the wild. Designated as CVE-2025-8110, this flaw allows authenticated users to execute a symlink bypass, leading to Remote Code Execution (RCE). As of …

1inch Named Exclusive Swap Provider at Launch for Ledger Multisig

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Road Town, British Virgin Islands, December 11th, 2025, CyberNewsWire 1inch, the leading DeFi ecosystem, has been selected as the exclusive swap provider at launch for Ledger Multisig, deepening the collaboration between the two projects. By integrating the 1inch Swap API …

Microsoft Teams to Introduce External Domains Anomalies Report for Enhanced Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft plans to enhance the administrative features of its Teams collaboration platform with a significant new security function to monitor external communications. Scheduled for rollout in February 2026, the “External Domains Anomalies Report” is designed to help IT administrators proactively …

New ClickFix Attacks as macOS Infostealer Leverages Official ChatGPT Website by Piggybacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malicious campaign is targeting macOS users via a novel attack that exploits ChatGPT’s official website. The attackers are using a technique called ClickFix to spread the AMOS infostealer by posting fake installation guides on the legitimate chatgpt.com domain. …

Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign has emerged that exploits legitimate AI platforms to deliver malicious code directly to unsuspecting users. Threat actors are using sponsored Google search results to redirect users searching for common macOS troubleshooting tips, such as “how to …

New “SOAPwn” .NET Vulnerabilities Expose Barracuda, Ivanti and Microsoft Appliances to RCE Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New research into legacy .NET Framework SOAP client code has uncovered “SOAPwn,” a class of vulnerabilities. That can be weaponized for remote code execution (RCE) across multiple enterprise products. Including Barracuda Service Center RMM, Ivanti Endpoint Manager, Umbraco CMS 8, …

Critical Vulnerability in Multiple India-Based CCTV Cameras Let Attackers Video and Account Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability affecting multiple India-based CCTV camera manufacturers has been disclosed. Potentially allowing attackers to access video feeds and steal account credentials without authentication. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on December 9, …