New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new information stealer called Sryxen has emerged in the underground malware market, targeting Windows systems with advanced techniques to harvest browser credentials and sensitive data. Sold as Malware-as-a-Service, this …

Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Legitimate administrative tools are increasingly becoming the weapon of choice for sophisticated threat actors aiming to blend in with normal network activity. A recent campaign has highlighted this dangerous trend, …

Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability in the Sneeit Framework WordPress plugin has come under active exploitation by threat actors, posing an immediate risk to thousands of websites worldwide. The …

Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Vim for Windows that could allow attackers to execute malicious code on users’ computers. The vulnerability, identified as CVE-2025-66476, affects Vim versions …

Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded …

CISA Releases Five ICS Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency released five critical Industrial Control Systems advisories on December 2, 2025, addressing significant security threats across industrial environments. These advisories cover vulnerabilities and active …

New Scanner Tool for Detecting Exposed ReactJS and Next.js RSC Endpoints (CVE-2025-55182)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security assessment tool has been released to help researchers and administrators identify React Server Components (RSC) endpoints potentially exposed to CVE-2025-55182. Developed as a lightweight by Pentester with …

New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security report reveals a troubling reality about the state of online phishing operations. Recent research has uncovered over 42,000 validated URLs and domains actively serving phishing kits, command-and-control …

Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign known as Operation DupeHike has emerged as a significant threat to Russian corporate environments, specifically targeting employees within human resources, payroll, and administrative departments. The campaign, …

Critical React and Next.js Enables Remote Attackers to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in React and Next.js could let remote attackers run malicious code on servers without logging in. The issue affects React Server Components (RSC) and the “Flight” …