North Korean Hackers Exploit React2Shell Vulnerability in the Wild to Deploy EtherRAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier. On December 5, 2025, just two days after the disclosure …

FortiSandbox OS command injection Vulnerability Let Attackers execute Malicious code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has released a critical security update for its FortiSandbox analysis appliances to fix a dangerous vulnerability. If left unpatched, this flaw could allow attackers to take control of the underlying system. The vulnerability, tracked as CVE-2025-53949, was officially published on …

Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security update addressing a dangerous Windows PowerShell vulnerability that allows attackers to execute malicious code on affected systems. The vulnerability, tracked as CVE-2025-54100, was publicly disclosed on December 9, 2025, and represents a significant security risk for organizations worldwide. The …

CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-priority warning regarding a critical security flaw in WinRAR, the popular file compression tool used by millions of Windows users. The vulnerability, tracked as CVE-2025-6218, is currently being exploited by attackers to compromise systems and execute malicious code. The specific …

Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability dubbed “GeminiJack” in Google Gemini Enterprise and previously Vertex AI Search that let attackers steal sensitive corporate data from Gmail, Calendar, and Docs with minimal effort. According to Noma Labs, it was considered an architectural flaw …

Microsoft 365 Services Disruption in Australia: Users Face Access Issues in Accessing Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Users across Australia are currently grappling with significant disruptions to critical business tools as Microsoft 365 services experience a widespread outage. The incident, which began on the morning of December 10, 2025, is preventing a large number of enterprise and …

Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild. Assigned the identifier CVE-2025-62221, this elevation of privilege flaw affects a wide …

Microsoft Patch Tuesday, December 2025 Edition

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed …

FortiOS, FortiWeb, and FortiProxy Vulnerability Lets Attackers Bypass FortiCloud SSO Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has issued an urgent security advisory regarding a critical vulnerability affecting its FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager product lines. The security flaw, identified as an Improper Verification of Cryptographic Signature (CWE-347), could allow an unauthenticated attacker to bypass the …

Microsoft December 2025 Patch Tuesday – 56 Vulnerabilities Fixed Including 3 Zero-days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released its final Patch Tuesday updates of 2025 on December 9, addressing 56 security vulnerabilities across Windows, Office, Exchange Server, and other components. This patch includes three zero-day flaws: two publicly disclosed remote code execution issues and one actively …