Microsoft Asks IT Admins to Contact for Fix Related to Windows IIS Failure Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that its December 2025 Windows security update (KB5071546, OS Build 19045.6691) is causing Message Queuing (MSMQ) failures, leading to widespread IIS site crashes. First reported on December …

Chinese Hackers Using Custom ShadowPad IIS Listener Module to Turn Compromised Servers into Active Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The group employs a custom ShadowPad IIS Listener module to transform compromised servers into a resilient, distributed relay network. This approach allows attackers to route malicious traffic through victim infrastructure, …

Singularity Linux Kernel Rootkit with New Feature Prevents Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Singularity, a sophisticated Linux kernel rootkit designed for Linux kernel versions 6.x, has gained significant attention from the cybersecurity community for its advanced stealth mechanisms and powerful capabilities. This kernel …

CISA Adds Fortinet Vulnerability to KEV Catalog After Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has officially added CVE-2025-59718 to its Known Exploited Vulnerabilities (KEV) catalog on December 16, 2025. Designating a critical deadline of December 23, 2025, for organizations to apply necessary remediation …

New Moonwalk++ PoC Shows How Malware Can Spoof Windows Call Stacks and Evade Elastic-Inspired Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated proof-of-concept demonstrating how malware can bypass advanced call stack detection mechanisms increasingly adopted by enterprise security vendors like Elastic. The new Moonwalk++ technique extends prior stack-spoofing research and reveals critical …

New ClickFix ‘Word Online’ Message Tricks Users into Installing DarkGate Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated social engineering campaign dubbed “ClickFix” has emerged, targeting users with deceptive “Word Online” error messages to distribute the formidable DarkGate malware. Unlike traditional drive-by downloads, this attack relies …

Chrome Zero-Day Vulnerabilities Exploited in 2025 – A Comprehensive Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Throughout 2025, Google addressed a significant wave of actively exploited zero-day vulnerabilities affecting its Chrome browser, patching a total of eight critical flaws that threatened billions of users worldwide. These …

Cellik Android Malware with One-Click APK Builder Let Attackers Wrap its Payload Inside with Google Play Store Apps

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cellik represents a significant evolution in Android Remote Access Trojan capabilities, introducing sophisticated device control and surveillance features previously reserved for advanced spyware. This newly identified RAT combines full device …

NVIDIA Isaac Lab Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security update addressing a dangerous deserialization vulnerability in NVIDIA Isaac Lab, a component of the NVIDIA Isaac Sim framework. The flaw could allow attackers to execute arbitrary code …

New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, …