CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to immediately address a critical security flaw in Oracle Identity Manager following reports of active exploitation. The vulnerability, tracked as CVE-2025-61757, allows unauthenticated remote attackers to execute arbitrary code on …

Cybersecurity News Weekly Newsletter – Fortinet, Chrome 0-Day Flaws, Cloudflare Outage and Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s edition of the Cybersecurity News Weekly Newsletter, where we analyze the critical incidents defining the current threat landscape. If this week has taught us anything, it is that the stability of our digital infrastructure is just …

Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels. The flaw, categorized as an authentication bypass vulnerability, poses an immediate risk to organizations that rely on Azure Bastion for …

Microsoft Confirms Windows 11 24H2 Update Broken Multiple Core Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially acknowledged a significant disruption affecting Windows 11 version 24H2 users, specifically after installing the cumulative update KB5062553 released in July 2025. The issue primarily affects environments using Virtual Desktop Infrastructure (VDI) and devices undergoing their first user …

ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce. The notorious hacking collective ShinyHunters is claiming responsibility for the intrusion, …

Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of …

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading …

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious hacking collective. The incident, which came to light late Thursday and Friday morning, involved the leak of internal screenshots on …

Phishing Breaks More Defenses Than Ever. Here’s the Fix 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If your tools say a link is clean, do you fully trust it?  Most SOC leaders don’t anymore, and for good reason. Phishing has become polished, quiet, and built to blend into everyday traffic. It slips through filters, lands in inboxes unnoticed, …

AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus detection methods while extracting sensitive user information. The threat actors …