SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered and reported by SonicWall’s security team. The flaw, tracked as CVE-2025-40601, …

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities, enabling machines to work on coding projects with minimal human intervention. GPT-5.1-Codex-Max operates differently from …

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. The U.S. Federal Bureau of Investigation also coordinated the action …

Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Salesforce has issued a critical security alert identifying “unusual activity” involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity may have enabled unauthorized access to Salesforce data through the applications’ external connections. In an …

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging a successful breach of the tech giant’s internal systems. This development is part of a massive extortion campaign exploiting a critical zero-day vulnerability in Oracle …

Mozilla Says It’s Finally Done With Two-Faced Onerep

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

In March 2024, Mozilla said it was winding down its collaboration with Onerep — an identity protection service offered with the Firefox web browser that promises to remove users from hundreds of people-search sites — after KrebsOnSecurity revealed Onerep’s founder …

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution flaw in Microsoft’s Windows Graphics Component allows attackers to seize control of systems using specially crafted JPEG images. With a CVSS score of 9.8, this vulnerability poses a severe threat to Windows users worldwide, as …

Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tsundere represents a significant shift in botnet tactics, leveraging the power of legitimate Node.js packages and blockchain technology to distribute malware across multiple operating systems. First identified around mid-2025 by Kaspersky GReAT researchers, this botnet demonstrates the evolving sophistication of …

Sturnus Banking Malware Steals Communications from Signal and WhatsApp, Gaining Full Control of The Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new banking malware called Sturnus has emerged as a significant threat to mobile users across Europe. Security researchers have discovered that this sophisticated Android trojan can capture encrypted messages from popular messaging apps like WhatsApp, Telegram, and Signal by …

Samourai Wallet Cryptocurrency Mixing Founders Jailed for Laundering Over $237 Million

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Attorney’s Office, Southern District of New York, has announced the sentencing of Keonne Rodriguez and William Lonergan Hill, co-founders of Samourai Wallet, a cryptocurrency mixing application designed specifically to hide illegal financial transactions. Rodriguez, who served as the …