NANOREMOTE Malware Leverages Google Drive API for Command-and-Control (C2) to Attack Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new Windows backdoor named NANOREMOTE emerged in October 2025, presenting a significant threat to enterprise environments by leveraging legitimate cloud infrastructure for malicious purposes. This fully-featured malware utilizes …

New BlackForce Phishing Kit Lets Attackers Steal Credentials Using MitB Attacks and Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing tool called BlackForce has emerged as a serious threat to organizations worldwide. First observed in August 2025, this professional-grade kit allows criminals to steal login information and …

Beware of Fake Leonardo DiCaprio Movie Torrent File Drops Agent Tesla Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat is targeting movie lovers who search for the latest films online. Cybercriminals are now using the popularity of Leonardo DiCaprio’s new film, One Battle After Another, to …

MITRE Releases Top 25 Most Dangerous Software Weaknesses of 2025

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MITRE has unveiled its 2025 Common Weakness Enumeration (CWE™) Top 25 Most Dangerous Software Weaknesses list, highlighting the root causes behind 39,080 Common Vulnerability and Exposure (CVE™) records this year. …

Windows Remote Access Connection Manager Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical privilege escalation flaws were disclosed in the Windows Remote Access Connection Manager on December 9, 2025. The vulnerabilities, tracked as CVE-2025-62472 and CVE-2025-62474, allow authorized attackers with low-level …

CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, …

New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Less than a week after addressing a critical Remote Code Execution (RCE) vulnerability, the React team has disclosed three additional security flaws affecting React Server Components (RSC). Security researchers discovered …

GitHub Down! Developers Frustrated by ‘No Server Available’ Message

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitHub is experiencing user-reported outages, with many developers greeted by a prominent error featuring the platform’s unicorn mascot and the message “No server is currently available to service your request.”​ …

Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular text editor Notepad++ has addressed a severe security weakness in its update mechanism that could allow attackers to hijack network traffic and push malicious executables to users under …

Gogs 0-Day Vulnerability Exploited in the Wild to Hack 700+ Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Gogs, a widely used self-hosted Git service, is currently being exploited in the wild. Designated as CVE-2025-8110, this flaw allows authenticated users to execute a …