Android Remote Data-Wipe Malware Attacking Users Leveraging Google’s Find Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated remote data-wipe attack targeting Android devices has emerged, exploiting Google’s Find Hub service to execute destructive operations on smartphones and tablets across South Korea. This campaign represents the …

Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Synology has released an urgent security update addressing a critical remote code execution vulnerability in BeeStation OS that allows unauthenticated attackers to execute arbitrary code on affected devices. The vulnerability, …

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted, plain-text nature of calendar invitations to …

Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages. The threat landscape shifted on November 5, 2025, when researchers identified nine malicious NuGet packages …

Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems. The flaw, tracked as CVE-2025-64740, has …

Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentication is completed. …

65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security investigation reveals that 65% of prominent AI companies have leaked verified secrets on GitHub, exposing API keys, tokens, and sensitive credentials that could compromise their operations and …

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure default …

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses in traditional email security defenses by targeting the world’s two …

Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight two high-severity issues alongside medium-rated flaws, underscoring the ongoing challenges …